<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:25:28.497141+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:18148</id>
    <title>ALSA-2025:18148 — Important: .NET 8.0 security update</title>
    <updated>2026-10-03T21:25:28.925858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-runtime-dbg-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-runtime-dbg-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-sdk-dbg-8.0 and 2 more</p>
<p>.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.</p>
<p>New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.121 and .NET Runtime 8.0.21.Security Fix(es):</p>
<p>* dotnet: .NET Information Disclosure Vulnerability (CVE-2025-55248)
  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2025-55315)
  * dotnet: .NET Denial of Service Vulnerability (CVE-2025-55247)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:18148"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-13247</id>
    <title>bdu:2025-13247</title>
    <updated>2026-10-03T21:25:28.925947+00:00</updated>
    <content>bdu:2025-13247</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-13247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-55315</id>
    <title>BELL-CVE-2025-55315</title>
    <updated>2026-10-03T21:25:28.925965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: dotnet8-runtime, Alpaquita:25: dotnet8-sdk, Alpaquita:stream: dotnet8-runtime, Alpaquita:stream: dotnet8-sdk</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-55315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0880</id>
    <title>certfr-2025-avi-0880 — De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Elles permettent à un attaquant de provoquer une é…</title>
    <updated>2026-10-03T21:25:28.925988+00:00</updated>
    <content>certfr-2025-avi-0880</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0880"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-269112</id>
    <title>EUVD-2026-269112</title>
    <updated>2026-10-03T21:25:28.926004+00:00</updated>
    <content>EUVD-2026-269112</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-269112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55315</id>
    <title>fkie_cve-2025-55315</title>
    <updated>2026-10-03T21:25:28.926014+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-55315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5rrx-jjjq-q2r5</id>
    <title>GHSA-5rrx-jjjq-q2r5 — Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability</title>
    <updated>2026-10-03T21:25:28.926036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: Microsoft.AspNetCore.Server.Kestrel.Core, NuGet: Microsoft.AspNetCore.App.Runtime.linux-arm, NuGet: Microsoft.AspNetCore.App.Runtime.linux-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-arm, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-x64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-x64, NuGet: Microsoft.AspNetCore.App.Runtime.osx-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.osx-x64, NuGet: Microsoft.AspNetCore.App.Runtime.win-arm and 3 more</p>
<p># Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability</p>
<p>## &lt;a name="executive-summary"&gt;&lt;/a&gt;Executive summary</p>
<p>Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 10.0 , ASP.NET Core 9.0 , ASP.NET Core 8.0, and ASP.NET Core 2.3. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.</p>
<p>Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.</p>
<p>## Discussion</p>
<p>Discussion for this issue can be found at https://github.com/dotnet/announcements/issues/371</p>
<p>### &lt;a name="mitigation-factors"&gt;&lt;/a&gt;Mitigation factors</p>
<p>Microsoft has not identified any mitigating factors for this vulnerability.</p>
<p>## &lt;a name="affected-software"&gt;&lt;/a&gt;Affected software</p>
<p>* Any ASP.NET Core 10.0 application running on ASP.NET Core 10.0.0-rc.1.25451.107 or earlier.
* Any ASP.NET Core 9.0 application running on ASP.NET Core 9.0.9 or earlier.
* Any ASP.NET Core application running on ASP.NET Core 8.0.20 or earlier.
* Any ASP.NET Core 2.x application consuming the package Microsoft.AspNetCore.Server.Kestrel.Core version 2.3.0 or earlier.</p>
<p>## &lt;a name="affected-packages"&gt;&lt;/a&gt;Affected Packages
The vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below</p>
<p>Package name | Affected version | Patched versio…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5rrx-jjjq-q2r5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-55315</id>
    <title>msrc_CVE-2025-55315 — ASP.NET Security Feature Bypass Vulnerability</title>
    <updated>2026-10-03T21:25:28.926157+00:00</updated>
    <content>msrc_CVE-2025-55315</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-55315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:20916</id>
    <title>RHBA-2025:20916 — Red Hat Bug Fix Advisory: .NET 10.0 bug fix and enhancement update</title>
    <updated>2026-10-03T21:25:28.926198+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:20916"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:20993</id>
    <title>RHBA-2025:20993 — Red Hat Bug Fix Advisory: .NET 10.0 bug fix and enhancement update</title>
    <updated>2026-10-03T21:25:28.926239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:20993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55315</id>
    <title>UBUNTU-CVE-2025-55315</title>
    <updated>2026-10-03T21:25:28.926269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet10, Ubuntu:24.04:LTS: dotnet8, Ubuntu:25.10: dotnet10, Ubuntu:25.10: dotnet8, Ubuntu:25.10: dotnet9, Ubuntu:26.04:LTS: dotnet10</p>
<p>Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-001</id>
    <title>VDE-2026-001 — METTLER TOLEDO: ASP.NET core vulnerability in LabX</title>
    <updated>2026-10-03T21:25:28.926326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LabX 21.2.12 (formerly known as LabX Cloud 1.2.12) is affected by the ASP.NET core vulnerability CVE-2025-55315.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-010</id>
    <title>VDE-2026-010 — WAGO: Multiple Vulnerabilities in WAGO Solution Builder and WAGO Device Sphere</title>
    <updated>2026-10-03T21:25:28.926354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been identified in WAGO Solution Builder and WAGO Device Sphere that affect components responsible for authentication and system communication.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2278</id>
    <title>WID-SEC-W-2025-2278 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:25:28.926399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, .NET Framework, Windows Server, ASP.NET, PowerShell und Windows ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2278"/>
  </entry>
</feed>
