Intel

AIKIDO-2025-10727

runtimepack.Microsoft.AspNetCore.App.Runtime.linux-arm is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CVE-2025-55315 Published Oct 22, 2025

99

Critical Risk

This Affects:

DOTNETruntimepack.Microsoft.AspNetCore.App.Runtime.linux-arm
8.0.0 - 8.0.20
Fixed in 8.0.21
9.0.0 - 9.0.9
Fixed in 9.0.10
Are you affected? Scan for Free

TL;DR

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

runtimepack.Microsoft.AspNetCore.App.Runtime.linux-arm is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 8.0.0 - 8.0.20 and 9.0.0 - 9.0.9.

How to fix this

Upgrade the Microsoft.AspNetCore.App.Runtime library to the patch version.