CVE-2025-55315
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
- Affected products
- Alt Linux, Asp.Net Core, Almalinux, Centos, Linuxmint, Red Hat, Red Os, Rocky Linux
- Microsoft Asp.net Core
- < 2.3.6, 8.0.21, 9.0.10
- Microsoft Visual Studio 2022
- < 17.10.20, 17.12.13, 17.14.17
- Fix
- Available
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 65.8% (99th percentile)
- Weakness
- CWE-444
- NVD status
- Modified
- Published
- 2025-10-14
CVE-2025-55315 at NVD
12 known exploits for CVE-2025-55315
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2025-55315-PoC-Exploit
CVE-2025-55315-detection-playground
CVE-2025-55315
CVE-2025-55315-
CVE-2025-55315-Scanner-Monitor
CVE-2025-55315-repro
CVE-2025-55315
π ASP.net 8.0.10 Core Kestrel HTTP Request Smuggling
ASP.net 8.0.10 - Bypass
π ASP.net 8.0.10 HTTP Request Smuggling / Authentication Bypass
Exploit for HTTP Request Smuggling in Microsoft
Exploit for CVE-2025-55315