vulns.co
/
GKData.io MCP

INInjection and untrusted input · 2 min read

Kestrel HTTP framing differed across proxy and application boundaries

A Kestrel request-framing report earned a researcher-reported USD 10,000 award.

Read the primary source INInjection and untrusted inputReviewed 2026-10-02

Root cause

Permissive HTTP framing validation could disagree with an upstream parser about message boundaries.

Demonstrated impact

Security controls could be bypassed in affected deployments. Consequences depended on the complete proxy/application architecture, not merely the presence of Kestrel.

Lessons for review

  • Define consistent message-boundary contracts across intermediaries and application servers; reject ambiguous framing.
  • Verify deployed runtimes and self-contained applications receive the applicable vendor updates.

Award and evidence

USD 10,000Bug Bounty · Researcher Reported

Exact award comes from the researcher. The July 31, 2025 official program announcement supplies USD context only; its later award-table changes do not establish this amount. Payment completion is unverified.

Read the primary researcher article and timeline, vendor advisory and July 2025 official USD-denominated program announcement.

  • The award and its date are researcher-reported, not independently vendor-confirmed.
  • Impact varies with deployment architecture; generic consequences are not evidence of actual victim compromise.
  • Dollar notation is interpreted through official program currency context; no conversion is used.

Recorded timeline

Published
2025-11-07explicit · Detailed article date; vendor disclosure preceded it.
Public Disclosure
2025-10-14explicit
Reported
2025-06-22explicit
Awarded
2025-07-21explicit
Fixed
2025-10-14explicit · Public patch release; vendor advisory independently identifies patched versions.

Sources and provenance

  1. ASP.NET Core CVE-2025-55315 disclosure and award timeline Siddhant Kalgutkar / Praetorian · reviewed 2026-10-02
  2. Microsoft Security Advisory CVE-2025-55315 Microsoft .NET security team · reviewed 2026-10-02
  3. .NET Bounty Program update, July 31, 2025 Madeline Eckert and Barry Dorrans / Microsoft · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software