Microsoft fixes highest-severity ASP.NET Core flaw ever
ID: 6bbcbf79-b4cd-576f-b453-b1259a11fe4c
STIX ID: report--6bbcbf79-b4cd-576f-b453-b1259a11fe4c
Feed Name: Bleeping Computer
Microsoft released patches for CVE-2025-55315, a high-severity HTTP request smuggling vulnerability in the Kestrel ASP.NET Core web server that could allow authenticated attackers to smuggle requests to hijack credentials, bypass front-end security controls (including CSRF checks), perform SSRF or injection attacks, or cause server crashes; fixes are available for ASP.NET Core 2.3/8.0/9.0, Visual Studio 2022 and related packages, and Microsoft urges updating, recompiling and redeploying where required.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
