PT-2025-42010 · Microsoft+8 · Asp.Net Core+8

Published

2025-10-14

·

Updated

2026-03-13

·

CVE-2025-55315

CVSS v3.1

9.9

Critical

AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions:
ASP.NET Core versions 3.0 through 7.0, and Kestrel ≤ 2.3.0
Description:
This vulnerability (CVE-2025-55315) is a critical HTTP request smuggling flaw in ASP.NET Core's Kestrel web server. It arises from inconsistent interpretation of HTTP requests, allowing an attacker to smuggle requests and potentially bypass security controls. This can lead to unauthorized access, data manipulation, and potentially remote code execution. The vulnerability is rated with the highest severity score (9.9) and is considered a significant risk. The flaw exists due to inconsistencies in how Kestrel parses HTTP requests, specifically with chunked encoding. Exploitation can allow attackers to hijack user sessions, conduct cross-site scripting (XSS) attacks, and potentially gain unauthorized access to sensitive data. The vulnerability affects QNAP NetBak PC Agent as well.
Recommendations:
Apply the latest security update released by Microsoft to address this vulnerability. Ensure all ASP.NET Core components, including Kestrel, are updated to the latest versions. If using QNAP NetBak PC Agent, reinstall the application to apply the necessary patches. Review and update request handling logic to mitigate potential risks.

Exploit

Fix

LPE

DoS

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

ALSA-2025:18148
ALSA-2025:18149
ALSA-2025:18150
ALSA-2025:18151
ALSA-2025:18152
ALSA-2025:18153
ALSA-2025_18148
ALSA-2025_18149
ALSA-2025_18150
ALSA-2025_18151
ALT-PU-2025-13072
ALT-PU-2025-13074
ALT-PU-2025-13673
ALT-PU-2025-13674
BDU:2025-13247
BIT-ASPNET-CORE-2025-55315
CESA-2025_18148
CESA-2025_18150
CVE-2025-55315
GHSA-5RRX-JJJQ-Q2R5
INFBA-2025_20916
INFSA-2025_18148
INFSA-2025_18149
INFSA-2025_18150
INFSA-2025_18151
RHSA-2025_18148
RHSA-2025_18149
RHSA-2025_18150
RHSA-2025_18151
USN-7822-1

Affected Products

Alt Linux
Asp.Net Core
Almalinux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu