Microsoft fixes one of its highest-rated security flaws of all time – here’s what happened


  • CVE-2025-55315 allows smuggling of HTTP requests in ASP.NET Core’s Kestrel web server
  • Attackers can bypass controls, access credentials, modify files, or crash the server.
  • Microsoft has released updates for affected .NET and Visual Studio versions to mitigate the flaw.

Microsoft has confirmed that it recently patched its “highest ever” vulnerability affecting its ASP.NET Core product.

Described as an “HTTP request smuggling bug,” the vulnerability is tracked as CVE-2025-55315 and received a severity score of 9.9/10 (critical).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top