Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2025-55315

ASP.NET Core Kestrel: HTTP request smuggling allows security feature bypass

Technology

.NET

CVSS Score

9.9 / 10.0

Affected Versions

ASP.NET Core 8.0.20 and earlier; 9.0.9 and earlier; 10.0.0-rc.1 and earlier; Microsoft.AspNetCore.Server.Kestrel.Core 2.3.0 and earlier

Upstream Fix

8.0.21; 9.0.10; 10.0.0-rc.2; updated Kestrel.Core 2.3 package

Published

October 14, 2025

OSSeva Coverage

Fixed upstream

Description

Inconsistent interpretation of HTTP requests in the ASP.NET Core Kestrel server allows request smuggling, letting an authorized attacker bypass a security feature over a network. Microsoft's advisory lists ASP.NET Core 8.0, 9.0 and 10.0 and the Kestrel.Core 2.3 package as affected and states that it has not identified any mitigating factors. CVSS is Microsoft's score as the CNA.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running ASP.NET Core 8.0.20 and earlier; 9.0.9 and earlier; 10.0.0-rc.1 and earlier; Microsoft.AspNetCore.Server.Kestrel.Core 2.3.0 and earlier, you need this patch. Book a discovery call to get covered.