Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-55315

82
FAUCET Score

CVE-2025-55315 is a critical HTTP request smuggling vulnerability in ASP.NET Core and Visual Studio 2022, allowing an authenticated attacker to bypass security features over a network due to inconsistent HTTP request interpretation. With a CVSS score of 9.9, this flaw is easily exploitable over the network with low complexity and user privileges, potentially leading to high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog or having public exploit code, the vulnerability has garnered significant community discussion and media attention, including a detailed blog post outlining its discovery.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.3.0, < 2.3.6CPE matchmatch criteria
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*
>= 8.0.0, < 8.0.21CPE matchmatch criteria
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.0.10CPE matchmatch criteria
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*
>= 17.10.0, < 17.10.20CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
>= 17.12.10, < 17.12.13CPE matchmatch criteria
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
65.84%
Probability of exploitation in next 30 days
EPSS Percentile
99.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-52492 · Apr 6, 2026
This CVE's current EPSS score of 0.6584 is in the 99th percentile among its peer group of 1,128 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (61)

microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.14Fixed in: 17.14.17
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.10Fixed in: 17.10.20
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.12Fixed in: 17.12.13
View patch
microsoftpatch availablevia msrc
Product: ASP.NET Core 2.3Fixed in: 2.3.6
View patch
microsoftpatch availablevia msrc
Product: ASP.NET Core 9.0Fixed in: 9.0.10
View patch
microsoftpatch availablevia msrc
Product: ASP.NET Core 8.0Fixed in: 8.0.21
View patch
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-x64Fixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.osx-arm64Fixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.osx-x64Fixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-armFixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-arm64Fixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-x64Fixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-x86Fixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-armFixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-musl-armFixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-musl-arm64Fixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-musl-x64Fixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-x64Fixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.osx-arm64Fixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.osx-x64Fixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-armFixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-arm64Fixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-x64Fixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-x86Fixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-armFixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-arm64Fixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-musl-armFixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-musl-arm64Fixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-musl-x64Fixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-x64Fixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.osx-arm64Fixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.osx-x64Fixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-armFixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-arm64Fixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-x64Fixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.win-x86Fixed in: 8.0.21
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.Server.Kestrel.CoreFixed in: 2.3.6
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-arm64Fixed in: 9.0.10
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-armFixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-arm64Fixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-musl-armFixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-musl-arm64Fixed in: 10.0.0-rc.2.25502.107
nugetpatch availablevia ghsa
Product: Microsoft.AspNetCore.App.Runtime.linux-musl-x64Fixed in: 10.0.0-rc.2.25502.107
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dotnet8.0-0:8.0.121-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dotnet8.0-0:8.0.121-1.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dotnet9.0-0:9.0.111-1.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: dotnet8.0-0:8.0.121-1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.25Fixed in: devspaces/udi-rhel9:sha256:8a19af8b03b59562335b3a3f77753944c27ecbccaeda3400d0f089a6cd8d11fa
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: dotnet9.0-0:9.0.111-1.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: dotnet10.0-0:10.0.100~rc.2.25502.107-0.12.el10_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dotnet9.0-0:9.0.111-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: dotnet8.0-0:8.0.121-1.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dotnet10.0-0:10.0.100~rc.2.25502.107-0.10.el9_7
View patch
asuswrtvendor investigatingvia llm_extracted
atlassianvendor investigatingvia llm_extracted
bindvendor investigatingvia llm_extracted
View patch
fobybusvendor investigatingvia llm_extracted
View patch
intelvendor investigatingvia llm_extracted
View patch
microsoftvendor investigatingvia nvd_reference
View patch
openmeetingsvendor investigatingvia llm_extracted
View patch
vllmvendor investigatingvia llm_extracted
View patch

Vendor Advisories (10)

redhatCVE-2025-55315Important

dotnet: .NET Security Feature Bypass Vulnerability

Oct 15, 2025
nugetGHSA-5rrx-jjjq-q2r5critical

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Oct 14, 2025
microsoft2025-Oct/CVE-2025-55315Important

ASP.NET Security Feature Bypass Vulnerability

Oct 14, 2025
vllmllm-vllm-6fc0cf74a39e494d

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Oct 14, 2025
atlassianllm-atlassian-f40371464c72f55b

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Oct 14, 2025
fobybusllm-fobybus-22de149de47ba991

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Oct 14, 2025
intelllm-intel-0516170a8ecc6f37

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Oct 14, 2025
openmeetingsllm-openmeetings-6b483d5bdf5bb189

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Oct 14, 2025
bindllm-bind-fa1e2a873423b6cf

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Oct 14, 2025
asuswrtllm-asuswrt-e981b74d38299416

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Oct 14, 2025

References

gist.github.com / N3mes1s/d0897c13ca199e739ecc2b562f466040
andrewlock.net / understanding-the-worst-dotnet-vulnerability-request-smuggling-and-cve-2025-55315
msrc.microsoft.com / update-guide/vulnerability/CVE-2025-55315
Vendor Advisory