← back
CVE-2025-55315criticalCWE-444

ASP.NET Security Feature Bypass Vulnerability

62Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 9.9epss 66%
from disclosure to weapon2 days
Published on NVDOct 14
1st PoC+2d
exploitation probability
66%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
In short

ASP.NET Core has a flaw that lets an authorized attacker send specially crafted HTTP requests to trick the server into processing malicious data that should have been blocked, bypassing built-in security protections.

Technical detail

HTTP request smuggling vulnerability in ASP.NET Core due to inconsistent interpretation of HTTP requests between the application and intermediate components. An authorized attacker can exploit this to bypass security features; the attack requires network access but no elevated privileges beyond basic authorization.

Summary generated and translated by AI from the official description.
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.