Microsoft fixes one of its security flaws with the “best ever” rating: this is what happened




  • CVE-2025-55315 enables HTTP request smuggling in the ASP.NET Core Kestrel web server
  • Attackers can bypass controls, access credentials, alter files, or crash the server.
  • Microsoft released updates for affected versions of .NET and Visual Studio to mitigate the flaw

Microsoft has confirmed that it recently fixed the “highest ever” vulnerability affecting its ASP.NET Core product.

Described as an “HTTP request smuggling bug,” the vulnerability is tracked as CVE-2025-55315 and was assigned a severity score of 9.9/10 (critical).



Leave a Comment

Your email address will not be published. Required fields are marked *