Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-55315
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ASP.NET Security Feature Bypass Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft ASP.NET Core 环境问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft ASP.NET Core是美国微软(Microsoft)公司的一框跨平台开源框架。该框架用于构建Web应用、物联网应用和移动后端等基于云的应用程序。 Microsoft ASP.NET Core存在环境问题漏洞,该漏洞源于攻击者利用该漏洞可以绕过某些功能。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
MicrosoftASP.NET Core 2.3 2.3 ~ 2.3.6 -
MicrosoftASP.NET Core 8.0 8.0 ~ 8.0.21 -
MicrosoftASP.NET Core 9.0 9.0 ~ 9.0.10 -
MicrosoftMicrosoft Visual Studio 2022 version 17.10 17.10.0 ~ 17.10.20 -
MicrosoftMicrosoft Visual Studio 2022 version 17.12 17.12.0 ~ 17.12.13 -
MicrosoftMicrosoft Visual Studio 2022 version 17.14 17.14.0 ~ 17.14.17 -
II. Public POCs for CVE-2025-55315
#POC DescriptionSource LinkShenlong Link
1Playground to experiment with different behavior on patched/unpatched Kestrel for the CVE-2025-55315 HTTP smuggling vulnerabilityhttps://github.com/nickcopi/CVE-2025-55315-detection-playgroundPOC Details
2Nonehttps://github.com/sirredbeard/CVE-2025-55315-reproPOC Details
3Nonehttps://github.com/snowcrashlord/CVE-2025-55315POC Details
4Nonehttps://github.com/RootAid/CVE-2025-55315POC Details
5Nonehttps://github.com/digitalsnemesis/CVE-2025-55315POC Details
6专业级HTTP请求走私漏洞利用与自动化渗透测试工具https://github.com/7huukdlnkjkjba/CVE-2025-55315-POC Details
7Quick and Simple Scripts to Scan for Vulnerable Servers and Packet Level Monitorshttps://github.com/jlinebau/CVE-2025-55315-Scanner-MonitorPOC Details
8Nonehttps://github.com/blackquantas/CVE-2025-55315POC Details
9CVE-2025-55315 PoC Exploithttps://github.com/ZemarKhos/CVE-2025-55315-PoC-ExploitPOC Details
10Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle requests past proxies and load balancers in vulnerable ASP.NET Core/Kestrel servers.https://github.com/MartinFabianIonut/CVE-2025-55315POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-55315
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-55315

No comments yet


Leave a comment