Description
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
Exploits (7)
nomisec
WORKING POC
45 stars
by sirredbeard · poc
https://github.com/sirredbeard/CVE-2025-55315-repro
github
WRITEUP
7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-55315.md
nomisec
WORKING POC
7 stars
by ZemarKhos · poc
https://github.com/ZemarKhos/CVE-2025-55315-PoC-Exploit
github
WORKING POC
6 stars
by 7huukdlnkjkjba · pythonpoc
https://github.com/7huukdlnkjkjba/CVE-2025-55315-
github
SCANNER
2 stars
by jlinebau · gopoc
https://github.com/jlinebau/CVE-2025-55315-Scanner-Monitor
nomisec
WORKING POC
1 stars
by MartinFabianIonut · poc
https://github.com/MartinFabianIonut/CVE-2025-55315
References (3)
Scores
CVSS v3
9.9
EPSS
0.0128
EPSS Percentile
79.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Lab Environment
COMMUNITY
+1 more images
Community Lab
+4 more repos
Details
CWE
CWE-444
Status
published
Products (15)
microsoft/asp.net_core
2.3.0 - 2.3.6
microsoft/visual_studio_2022
17.10.0 - 17.10.20
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm
10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64
10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm
10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64
10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64
10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64
10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64
10.0.0-rc.1.25451.107 - 10.0.0-rc.2.25502.107NuGet
... and 5 more
Published
Oct 14, 2025
Tracked Since
Feb 18, 2026