icon

We found results for “

CVE-2025-55315

Good to know:

icon
icon

Date: October 14, 2025

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

Severity Score

Severity Score

Weakness Type (CWE)

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CWE-444

Top Fix

icon

Upgrade Version

Upgrade to version microsoft.aspnetcore.server.kestrel.core - 2.3.6;microsoft.aspnetcore.app.runtime.linux-arm - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.linux-arm - 9.0.10;microsoft.aspnetcore.app.runtime.linux-arm - 8.0.21;microsoft.aspnetcore.app.runtime.linux-arm64 - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.linux-arm64 - 9.0.10;microsoft.aspnetcore.app.runtime.linux-arm64 - 8.0.21;microsoft.aspnetcore.app.runtime.linux-musl-arm - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.linux-musl-arm - 9.0.10;microsoft.aspnetcore.app.runtime.linux-musl-arm - 8.0.21;microsoft.aspnetcore.app.runtime.linux-musl-arm64 - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.linux-musl-arm64 - 9.0.10;microsoft.aspnetcore.app.runtime.linux-musl-arm64 - 8.0.21;microsoft.aspnetcore.app.runtime.linux-musl-x64 - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.linux-musl-x64 - 9.0.10;microsoft.aspnetcore.app.runtime.linux-musl-x64 - 8.0.21;microsoft.aspnetcore.app.runtime.linux-x64 - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.linux-x64 - 9.0.10;microsoft.aspnetcore.app.runtime.linux-x64 - 8.0.21;microsoft.aspnetcore.app.runtime.osx-arm64 - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.osx-arm64 - 9.0.10;microsoft.aspnetcore.app.runtime.osx-arm64 - 8.0.21;microsoft.aspnetcore.app.runtime.osx-x64 - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.osx-x64 - 9.0.10;microsoft.aspnetcore.app.runtime.osx-x64 - 8.0.21;microsoft.aspnetcore.app.runtime.win-arm64 - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.win-arm64 - 9.0.10;microsoft.aspnetcore.app.runtime.win-arm64 - 8.0.21;microsoft.aspnetcore.app.runtime.win-x64 - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.win-x64 - 9.0.10;microsoft.aspnetcore.app.runtime.win-x64 - 8.0.21;microsoft.aspnetcore.app.runtime.win-x86 - 10.0.0-rc.2.25502.107;microsoft.aspnetcore.app.runtime.win-x86 - 9.0.10;microsoft.aspnetcore.app.runtime.win-x86 - 8.0.21

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): LOW

Do you need more information?

Contact Us