CVE-2025-55315
ASP.NET Core Kestrel: HTTP request smuggling allows security feature bypass
Technology
.NET
CVSS Score
9.9 / 10.0
Affected Versions
ASP.NET Core 8.0.20 and earlier; 9.0.9 and earlier; 10.0.0-rc.1 and earlier; Microsoft.AspNetCore.Server.Kestrel.Core 2.3.0 and earlier
Upstream Fix
8.0.21; 9.0.10; 10.0.0-rc.2; updated Kestrel.Core 2.3 package
Published
October 14, 2025
OSSeva Coverage
Fixed upstream
Description
Inconsistent interpretation of HTTP requests in the ASP.NET Core Kestrel server allows request smuggling, letting an authorized attacker bypass a security feature over a network. Microsoft's advisory lists ASP.NET Core 8.0, 9.0 and 10.0 and the Kestrel.Core 2.3 package as affected and states that it has not identified any mitigating factors. CVSS is Microsoft's score as the CNA.
Is your .NET deployment affected?
If you're running ASP.NET Core 8.0.20 and earlier; 9.0.9 and earlier; 10.0.0-rc.1 and earlier; Microsoft.AspNetCore.Server.Kestrel.Core 2.3.0 and earlier, you need this patch. Book a discovery call to get covered.