TOP BLOG
- 16th October 2025
A newly disclosed vulnerability in Microsoft ASP.NET Core’s Kestrel web server (CVE-2025-55315) allows HTTP Request Smuggling attacks that can bypass authentication, inject hidden requests, and compromise session integrity. Rated CVSS 9.9, this issue impacts all supported versions of .NET and Visual Studio 2022. External-facing or proxy-misconfigured applications are at highest risk. Immediate patching is strongly advised.
A newly disclosed vulnerability in Microsoft ASP.NET Core’s Kestrel web server (CVE-2025-55315) allows HTTP Request Smuggling attacks that can bypass authentication, inject hidden requests, and compromise session integrity. Rated CVSS 9.9, this issue impacts all supported versions of .NET and Visual Studio 2022. External-facing or proxy-misconfigured applications are at highest risk. Immediate patching is strongly advised.
Francesco Cipollone
- No Responses