CVE-2022-26924 describes a Denial of Service vulnerability affecting Microsoft's Yet Another Reverse Proxy (YARP). With a CVSS score of 7.5 (HIGH), this vulnerability can be exploited remotely without authentication or user interaction, leading to a complete denial of service. While no public exploit code or active exploitation has been observed, its presence on Microsoft's April 2022 Patch Tuesday and limited community discussion indicate awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:yet_another_reverse_proxy:1.0.0:*:*:*:*:*:*:* | ||
1.1.0CPE matchmatch criteria | cpe:2.3:a:microsoft:yet_another_reverse_proxy:1.1.0:rc1.22152.1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.