Vulnerability record · CVE-2025-55315 · published 14 October 2025
CVE-2025-55315: ASP.NET Core HTTP request smuggling bypasses security features
Microsoft · Asp.Net Core
ASP.NET Core inconsistently interprets HTTP requests, enabling HTTP request/response smuggling (CWE-444). An attacker who already holds some authorization can bypass security controls over the network, which matters because smuggling can desynchronize front-end and back-end request handling and defeat access checks.
Description
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Automated analysis
high priorityCritical CVSS (9.9) and very high EPSS with a network-reachable security bypass, tempered by the requirement for low privileges and no confirmed in-the-wild exploitation.
What it is
ASP.NET Core inconsistently interprets HTTP requests, enabling HTTP request/response smuggling (CWE-444). An attacker who already holds some authorization can bypass security controls over the network, which matters because smuggling can desynchronize front-end and back-end request handling and defeat access checks.
Impact
An authorized attacker can bypass a security feature, potentially reaching resources or actions that should be blocked and poisoning or splitting requests handled by intermediaries. The CVSS vector indicates high confidentiality and integrity impact with some availability impact.
Attack surface
Reachable over the network (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), meaning the attacker needs some valid authorization first. No specific endpoint or protocol detail is given beyond HTTP handling in ASP.NET Core.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.66 (99th percentile), indicating elevated likelihood of exploitation activity. Reference tags are only Vendor Advisory plus two untagged third-party write-ups, so no confirmed in-the-wild exploitation is stated.
What to do
- Apply the Microsoft MSRC update for CVE-2025-55315 to affected ASP.NET Core runtimes and Visual Studio 2022 installations.
- Inventory internet-facing ASP.NET Core applications and any front-end proxies or load balancers that forward HTTP to them, and confirm consistent request parsing across tiers.
- Enforce strict HTTP parsing and reject ambiguous or malformed requests (conflicting Content-Length and Transfer-Encoding, duplicate headers) at the edge.
- Reduce the blast radius by reviewing what low-privileged authenticated users can reach, since the flaw requires only low privileges to trigger.
- Monitor vendor advisories for updated guidance, as the record does not list specific affected versions.
Detection
- Inspect proxy and application logs for request desynchronization signs: mismatched Content-Length and Transfer-Encoding headers, duplicate or obfuscated headers, and requests that produce unexpected 400/500 responses.
- Correlate front-end proxy logs with back-end ASP.NET Core request logs to find requests seen by one tier but not the other, or with differing paths and methods.
- Alert on anomalous sequences of pipelined requests or smuggled-prefix patterns from a single authenticated session.
- Track authentication events where a low-privileged user accesses endpoints or data outside their expected authorization scope.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-55315 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-55315), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.