CVE-2025-55315

CRITICAL9.9EPSS 1.7%

ASP.NET Security Feature Bypass Vulnerability

發布日:2025/10/14修改日:2025/11/6
也稱為:GHSA-5rrx-jjjq-q2r5BIT-aspnet-core-2025-55315

描述

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

受影響套件(14)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.9CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

參考連結(7)