VYPR
Critical severityNVD Advisory· Published Oct 14, 2025· Updated Feb 22, 2026

ASP.NET Security Feature Bypass Vulnerability

CVE-2025-55315

Description

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.AspNetCore.Server.Kestrel.CoreNuGet
< 2.3.62.3.6
Microsoft.AspNetCore.App.Runtime.linux-armNuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.linux-musl-armNuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.osx-arm64NuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.win-armNuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.win-x64NuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.win-x86NuGet
>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.10710.0.0-rc.2.25502.107
Microsoft.AspNetCore.App.Runtime.linux-armNuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.linux-musl-armNuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.osx-arm64NuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.win-armNuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.win-x64NuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.win-x86NuGet
>= 9.0.0, < 9.0.109.0.10
Microsoft.AspNetCore.App.Runtime.linux-armNuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.linux-musl-armNuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.osx-arm64NuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.win-armNuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.win-x64NuGet
>= 8.0.0, < 8.0.218.0.21
Microsoft.AspNetCore.App.Runtime.win-x86NuGet
>= 8.0.0, < 8.0.218.0.21

Affected products

95

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.