Microsoft fixes one of its “highest rated security flaws ever” – here’s what happened


  • CVE-2025-55315 allows HTTP request spoofing in ASP.NET Core’s Kestrel web server
  • Attackers can bypass controls, gain access to credentials, modify files, or crash the server
  • Microsoft released updates to affected .NET and Visual Studio versions to address the bug

Microsoft has confirmed that it has recently patched its “highest-ever” vulnerability plaguing its ASP.NET Core product.

Described as an “HTTP request smuggling flaw,” the vulnerability is tracked as CVE-2025-55315 and was given a severity score of 9.9/10 (Critical).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top