Important CVSS 9.9 EPSS 0.65838 2025-10 archive

Executive Summary

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

Overview

9.9
CVSS CRITICAL
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Security Feature Bypass
Released Oct 14 2025
Last Updated Oct 14 2025
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.65838 — 0.99204 percentile
NVD CVSS 9.9 CRITICAL — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Changed
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
Low
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 8.6

EPSS Score

0.65838
probability of exploitation in the next 30 days
0.99204 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

6 affected products
Product KB Article Severity Impact Restart Required
ASP.NET Core 2.3 Release Notes (Security Update) Important Security Feature Bypass Maybe
ASP.NET Core 8.0 5068331 (Security Update) Important Security Feature Bypass Maybe
ASP.NET Core 9.0 5068332 (Security Update) Important Security Feature Bypass Maybe
Microsoft Visual Studio 2022 version 17.10 Release Notes (Security Update) Important Security Feature Bypass Maybe
Microsoft Visual Studio 2022 version 17.12 Release Notes (Security Update) Important Security Feature Bypass Maybe
Microsoft Visual Studio 2022 version 17.14 Release Notes (Security Update) Important Security Feature Bypass Maybe

Patches

3 patches
Article Type Restart
Release Notes Security Update Maybe
5068331 Security Update Maybe
5068332 Security Update Maybe

Exploits & PoC

7 public PoCs
RepositoryStarsPublishedDescription
sirredbeard/CVE-2025-55315-repro 46 2025-10-16 Tool that reproduces CVE-2025-55315 in ASP.NET Core.
ZemarKhos/CVE-2025-55315-PoC-Exploit 9 2025-11-11 CVE-2025-55315 PoC Exploit
nickcopi/CVE-2025-55315-detection-playground 7 2025-10-16 Playground to experiment with different behavior on patched/unpatched Kestrel for the CVE-2025-55315 HTTP smuggling vulnerability
7huukdlnkjkjba/CVE-2025-55315- 6 2025-10-19 专业级HTTP请求走私漏洞利用与自动化渗透测试工具
jlinebau/CVE-2025-55315-Scanner-Monitor 2 2025-10-24 Quick and Simple Scripts to Scan for Vulnerable Servers and Packet Level Monitors
MartinFabianIonut/CVE-2025-55315 1 2025-11-27 Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle requests past proxies and load balancers in vulner
NetVanguard-cmd/CVE-2025-55315 0 2026-04-19

Detection Rules

Acknowledgments

Sid