CVE-2025-55315

CRITICAL LAB

ASP.NET Core - SSRF

Title source: llm

Description

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

Exploits (7)

nomisec WORKING POC 45 stars
by sirredbeard · poc
https://github.com/sirredbeard/CVE-2025-55315-repro
github WRITEUP 7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-55315.md
nomisec WORKING POC 7 stars
by ZemarKhos · poc
https://github.com/ZemarKhos/CVE-2025-55315-PoC-Exploit
github WORKING POC 6 stars
by 7huukdlnkjkjba · pythonpoc
https://github.com/7huukdlnkjkjba/CVE-2025-55315-
github SCANNER 2 stars
by jlinebau · gopoc
https://github.com/jlinebau/CVE-2025-55315-Scanner-Monitor
nomisec WORKING POC 1 stars
by MartinFabianIonut · poc
https://github.com/MartinFabianIonut/CVE-2025-55315
nomisec STUB
by NetVanguard-cmd · poc
https://github.com/NetVanguard-cmd/CVE-2025-55315

Scores

CVSS v3 9.9
EPSS 0.0128
EPSS Percentile 79.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Lab Environment

COMMUNITY
Community Lab
docker pull mcr.microsoft.com/dotnet/sdk:10.0.100-rc.1
docker pull mcr.microsoft.com/dotnet/aspnet:10.0.0-rc.1
docker pull unsafe-api:latest
docker pull safe-api:latest
docker pull python-proxy:latest
+1 more images
+4 more repos

Details

CWE
CWE-444
Status published
Products (15)
microsoft/asp.net_core 2.3.0 - 2.3.6
microsoft/visual_studio_2022 17.10.0 - 17.10.20
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm 10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm 10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64 10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
... and 5 more
Published Oct 14, 2025
Tracked Since Feb 18, 2026