← Vulnerability feed

Vulnerability record · CVE-2025-55315 · published 14 October 2025

CVE-2025-55315: ASP.NET Core HTTP request smuggling bypasses security features

Microsoft · Asp.Net Core

ASP.NET Core inconsistently interprets HTTP requests, enabling HTTP request/response smuggling (CWE-444). An attacker who already holds some authorization can bypass security controls over the network, which matters because smuggling can desynchronize front-end and back-end request handling and defeat access checks.

9.9 CVSS 3.1 Critical EPSS 66% · top 0.7% CWE-444 · HTTP request smuggling
9.9CVSS 3.1 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCritical CVSS (9.9) and very high EPSS with a network-reachable security bypass, tempered by the requirement for low privileges and no confirmed in-the-wild exploitation.

What it is

ASP.NET Core inconsistently interprets HTTP requests, enabling HTTP request/response smuggling (CWE-444). An attacker who already holds some authorization can bypass security controls over the network, which matters because smuggling can desynchronize front-end and back-end request handling and defeat access checks.

Impact

An authorized attacker can bypass a security feature, potentially reaching resources or actions that should be blocked and poisoning or splitting requests handled by intermediaries. The CVSS vector indicates high confidentiality and integrity impact with some availability impact.

Attack surface

Reachable over the network (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), meaning the attacker needs some valid authorization first. No specific endpoint or protocol detail is given beyond HTTP handling in ASP.NET Core.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.66 (99th percentile), indicating elevated likelihood of exploitation activity. Reference tags are only Vendor Advisory plus two untagged third-party write-ups, so no confirmed in-the-wild exploitation is stated.

What to do

  • Apply the Microsoft MSRC update for CVE-2025-55315 to affected ASP.NET Core runtimes and Visual Studio 2022 installations.
  • Inventory internet-facing ASP.NET Core applications and any front-end proxies or load balancers that forward HTTP to them, and confirm consistent request parsing across tiers.
  • Enforce strict HTTP parsing and reject ambiguous or malformed requests (conflicting Content-Length and Transfer-Encoding, duplicate headers) at the edge.
  • Reduce the blast radius by reviewing what low-privileged authenticated users can reach, since the flaw requires only low privileges to trigger.
  • Monitor vendor advisories for updated guidance, as the record does not list specific affected versions.

Detection

  • Inspect proxy and application logs for request desynchronization signs: mismatched Content-Length and Transfer-Encoding headers, duplicate or obfuscated headers, and requests that produce unexpected 400/500 responses.
  • Correlate front-end proxy logs with back-end ASP.NET Core request logs to find requests seen by one tier but not the other, or with differing paths and methods.
  • Alert on anomalous sequences of pipelined requests or smuggled-prefix patterns from a single authenticated session.
  • Track authentication events where a low-privileged user accesses endpoints or data outside their expected authorization scope.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-55315 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2023-38180Microsoft .NET and Visual Studio uncontrolled resource consumption DoSCVE-2023-38180 is a denial-of-service flaw in Microsoft .NET, ASP.NET Core and Visual Studio 2022, classified as uncontrolled resource consumption (C…KEVEPSS 14%analysed9.8CVE-2026-47304Microsoft .net framework insufficient verification of data authenticity vulnerabilityImproper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.EPSS 0.29%9.8CVE-2024-43498Microsoft .net type confusion vulnerability.NET and Visual Studio Remote Code Execution VulnerabilityEPSS 3.6%9.8CVE-2024-0057Microsoft powershell improper input validation vulnerabilityNET, .NET Framework, and Visual Studio Security Feature Bypass VulnerabilityEPSS 2.8%9.8CVE-2023-36049Microsoft .net framework improper input validation vulnerability.NET, .NET Framework, and Visual Studio Elevation of Privilege VulnerabilityEPSS 13%9.8CVE-2023-36758Microsoft visual studio 2022 link following vulnerabilityVisual Studio Elevation of Privilege VulnerabilityEPSS 1.3%9.1CVE-2026-40372Microsoft asp.net core improper verification of cryptographic signature vulnerabilityImproper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.EPSS 0.82%

Source: NIST National Vulnerability Database (record CVE-2025-55315), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.