CVE-2025-55315: Microsoft ASP.NET Core

Critical severity, CVSS 9.9. EPSS: 65.9% chance of exploitation in the next 30 days.

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

Affected products

  • Microsoft ASP.NET Core: from 2.3.0, before 2.3.6 (fixed in 2.3.6); from 8.0.0, before 8.0.21 (fixed in 8.0.21); from 9.0.0, before 9.0.10 (fixed in 9.0.10)
  • Microsoft Visual Studio 2022: from 17.10.0, before 17.10.20 (fixed in 17.10.20); from 17.12.10, before 17.12.13 (fixed in 17.12.13); from 17.14.0, before 17.14.17 (fixed in 17.14.17)

Published 2025-10-14. Last modified 2026-06-17.