PoC Index

CVE-2025-55315

CRITICAL 9.9EPSS 65.8%

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

CVSS v3.1
9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
CVSS v3.1
9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
EPSS
65.84% chance of exploitation in the next 30 days, 99th percentile
Published
2025-10-14
Updated
2026-02-22

Proof-of-concept exploits (4)

ExploitDB entries (1)

References

Related