Root cause
Permissive HTTP framing validation could disagree with an upstream parser about message boundaries.
Demonstrated impact
Security controls could be bypassed in affected deployments. Consequences depended on the complete proxy/application architecture, not merely the presence of Kestrel.
Lessons for review
- Define consistent message-boundary contracts across intermediaries and application servers; reject ambiguous framing.
- Verify deployed runtimes and self-contained applications receive the applicable vendor updates.
Award and evidence
Exact award comes from the researcher. The July 31, 2025 official program announcement supplies USD context only; its later award-table changes do not establish this amount. Payment completion is unverified.
Read the primary researcher article and timeline, vendor advisory and July 2025 official USD-denominated program announcement.
- The award and its date are researcher-reported, not independently vendor-confirmed.
- Impact varies with deployment architecture; generic consequences are not evidence of actual victim compromise.
- Dollar notation is interpreted through official program currency context; no conversion is used.
Recorded timeline
- Published
- 2025-11-07explicit · Detailed article date; vendor disclosure preceded it.
- Public Disclosure
- 2025-10-14explicit
- Reported
- 2025-06-22explicit
- Awarded
- 2025-07-21explicit
- Fixed
- 2025-10-14explicit · Public patch release; vendor advisory independently identifies patched versions.
Sources and provenance
- ASP.NET Core CVE-2025-55315 disclosure and award timeline Siddhant Kalgutkar / Praetorian · reviewed 2026-10-02
- Microsoft Security Advisory CVE-2025-55315 Microsoft .NET security team · reviewed 2026-10-02
- .NET Bounty Program update, July 31, 2025 Madeline Eckert and Barry Dorrans / Microsoft · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.