CVE-2025-55315

Published: October 16, 2025Last modified: October 30, 2025

Description

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

Severity score breakdown

ParameterValue
Base score9.9
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux25 LTSdotnet8-runtimeFixed (8.0.21-r0)
dotnet8-sdkVulnerable (8.0.117-r0)
Streamdotnet8-runtimeFixed (8.0.21-r0)
dotnet8-sdkVulnerable (8.0.117-r0)

References

ON THIS PAGE