logo

Microsoft fixes highest-severity ASP.NET Core flaw ever

ID: 6bbcbf79-b4cd-576f-b453-b1259a11fe4c

STIX ID: report--6bbcbf79-b4cd-576f-b453-b1259a11fe4c

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-17

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Microsoft released patches for CVE-2025-55315, a high-severity HTTP request smuggling vulnerability in the Kestrel ASP.NET Core web server that could allow authenticated attackers to smuggle requests to hijack credentials, bypass front-end security controls (including CSRF checks), perform SSRF or injection attacks, or cause server crashes; fixes are available for ASP.NET Core 2.3/8.0/9.0, Visual Studio 2022 and related packages, and Microsoft urges updating, recompiling and redeploying where required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.