Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2025-55315

Severity
9.9CRITICAL
EPSS
1.3%
top 20.39%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 14
Latest updateApr 6

Description

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:LExploitability: 3.1 | Impact: 6.0

Affected Packages24 packages

NVDmicrosoft/asp.net_core2.3.02.3.6+2
CVEListV5microsoft/asp.net_core_2.32.32.3.6
CVEListV5microsoft/asp.net_core_8.08.08.0.21
CVEListV5microsoft/asp.net_core_9.09.09.0.10
NuGetMicrosoft.AspNetCore.App.Runtime.osx-x6410.0.0-rc.1.25451.10710.0.0-rc.2.25502.107+2

🔴Vulnerability Details

5
OSV
dotnet8, dotnet9, dotnet10 vulnerabilities2025-10-16
GHSA
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability2025-10-14
CVEList
ASP.NET Security Feature Bypass Vulnerability2025-10-14
OSV
CVE-2025-55315: Inconsistent interpretation of http requests ('http request/response smuggling') in ASP2025-10-14
OSV
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability2025-10-14

💥Exploits & PoCs

1
Exploit-DB
ASP.net 8.0.10 - Bypass2026-04-06

📋Vendor Advisories

3
Ubuntu
.NET vulnerabilities2025-10-16
Red Hat
dotnet: .NET Security Feature Bypass Vulnerability2025-10-15
Microsoft
ASP.NET Security Feature Bypass Vulnerability2025-10-14

🕵️Threat Intelligence

1
Bleepingcomputer
QNAP warns of critical ASP.NET flaw in its Windows backup software2025-10-27