CVE-2025-55315
CRITICAL9.9EPSS 1.7%ASP.NET Security Feature Bypass Vulnerability
發布日:2025/10/14修改日:2025/11/6
描述
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
受影響套件(14)
- Bitnami/aspnet-core>= 2.3.0, < 2.3.6, >= 8.0.0, < 8.0.21, >= 9.0.0, < 9.0.10
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-arm>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-arm64>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-musl-arm>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-musl-x64>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-x64>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.osx-arm64>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.osx-x64>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.win-arm>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.win-arm64>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.win-x64>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.App.Runtime.win-x86>= 10.0.0-rc.1.25451.107, < 10.0.0-rc.2.25502.107
- NuGet/Microsoft.AspNetCore.Server.Kestrel.Corefrom 0, < 2.3.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.9 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-55315
- PATCHhttps://github.com/dotnet/aspnetcore
- WEBhttps://andrewlock.net/understanding-the-worst-dotnet-vulnerability-request-smuggling-and-cve-2025-55315/
- WEBhttps://gist.github.com/N3mes1s/d0897c13ca199e739ecc2b562f466040
- WEBhttps://github.com/dotnet/announcements/issues/371
- WEBhttps://github.com/dotnet/aspnetcore/security/advisories/GHSA-5rrx-jjjq-q2r5
- WEBhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55315