<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:04:49 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:18148 — Important: .NET 8.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:18148</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-runtime-dbg-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-runtime-dbg-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-sdk-dbg-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.121 and .NET Runtime 8.0.21.Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Information Disclosure Vulnerability (CVE-2025-55248)
  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2025-55315)
  * dotnet: .NET Denial of Service Vulnerability (CVE-2025-55247)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-runtime-dbg-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-runtime-dbg-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-sdk-dbg-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.121 and .NET Runtime 8.0.21.Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Information Disclosure Vulnerability (CVE-2025-55248)
  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2025-55315)
  * dotnet: .NET Denial of Service Vulnerability (CVE-2025-55247)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:18148</guid>
    </item>
    <item>
      <title>bdu:2025-13247</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13247</link>
      <description>bdu:2025-13247</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13247</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-55315</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-55315</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: dotnet8-runtime, Alpaquita:25: dotnet8-sdk, Alpaquita:stream: dotnet8-runtime, Alpaquita:stream: dotnet8-sdk&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: dotnet8-runtime, Alpaquita:25: dotnet8-sdk, Alpaquita:stream: dotnet8-runtime, Alpaquita:stream: dotnet8-sdk&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-55315</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0880 — De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Elles permettent à un attaquant de provoquer une é…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0880</link>
      <description>certfr-2025-avi-0880</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0880</guid>
    </item>
    <item>
      <title>EUVD-2026-269112</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-269112</link>
      <description>EUVD-2026-269112</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-269112</guid>
    </item>
    <item>
      <title>fkie_cve-2025-55315</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55315</link>
      <description>&lt;p&gt;Inconsistent interpretation of http requests (&amp;#39;http request/response smuggling&amp;#39;) in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Inconsistent interpretation of http requests (&amp;#39;http request/response smuggling&amp;#39;) in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-55315</guid>
    </item>
    <item>
      <title>GHSA-5rrx-jjjq-q2r5 — Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5rrx-jjjq-q2r5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Microsoft.AspNetCore.Server.Kestrel.Core, NuGet: Microsoft.AspNetCore.App.Runtime.linux-arm, NuGet: Microsoft.AspNetCore.App.Runtime.linux-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-arm, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-x64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-x64, NuGet: Microsoft.AspNetCore.App.Runtime.osx-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.osx-x64, NuGet: Microsoft.AspNetCore.App.Runtime.win-arm and 3 more&lt;/p&gt;
&lt;p&gt;# Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;executive-summary&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Executive summary&lt;/p&gt;
&lt;p&gt;Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 10.0 , ASP.NET Core 9.0 , ASP.NET Core 8.0, and ASP.NET Core 2.3. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.&lt;/p&gt;
&lt;p&gt;Inconsistent interpretation of http requests (&amp;#39;http request/response smuggling&amp;#39;) in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.&lt;/p&gt;
&lt;p&gt;## Discussion&lt;/p&gt;
&lt;p&gt;Discussion for this issue can be found at https://github.com/dotnet/announcements/issues/371&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;mitigation-factors&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Mitigation factors&lt;/p&gt;
&lt;p&gt;Microsoft has not identified any mitigating factors for this vulnerability.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-software&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected software&lt;/p&gt;
&lt;p&gt;* Any ASP.NET Core 10.0 application running on ASP.NET Core 10.0.0-rc.1.25451.107 or earlier.
* Any ASP.NET Core 9.0 application running on ASP.NET Core 9.0.9 or earlier.
* Any ASP.NET Core application running on ASP.NET Core 8.0.20 or earlier.
* Any ASP.NET Core 2.x application consuming the package Microsoft.AspNetCore.Server.Kestrel.Core version 2.3.0 or earlier.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-packages&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected Packages
The vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below&lt;/p&gt;
&lt;p&gt;Package name | Affected version | Patched versio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Microsoft.AspNetCore.Server.Kestrel.Core, NuGet: Microsoft.AspNetCore.App.Runtime.linux-arm, NuGet: Microsoft.AspNetCore.App.Runtime.linux-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-arm, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-x64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-x64, NuGet: Microsoft.AspNetCore.App.Runtime.osx-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.osx-x64, NuGet: Microsoft.AspNetCore.App.Runtime.win-arm and 3 more&lt;/p&gt;
&lt;p&gt;# Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;executive-summary&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Executive summary&lt;/p&gt;
&lt;p&gt;Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 10.0 , ASP.NET Core 9.0 , ASP.NET Core 8.0, and ASP.NET Core 2.3. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability.&lt;/p&gt;
&lt;p&gt;Inconsistent interpretation of http requests (&amp;#39;http request/response smuggling&amp;#39;) in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.&lt;/p&gt;
&lt;p&gt;## Discussion&lt;/p&gt;
&lt;p&gt;Discussion for this issue can be found at https://github.com/dotnet/announcements/issues/371&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;mitigation-factors&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Mitigation factors&lt;/p&gt;
&lt;p&gt;Microsoft has not identified any mitigating factors for this vulnerability.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-software&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected software&lt;/p&gt;
&lt;p&gt;* Any ASP.NET Core 10.0 application running on ASP.NET Core 10.0.0-rc.1.25451.107 or earlier.
* Any ASP.NET Core 9.0 application running on ASP.NET Core 9.0.9 or earlier.
* Any ASP.NET Core application running on ASP.NET Core 8.0.20 or earlier.
* Any ASP.NET Core 2.x application consuming the package Microsoft.AspNetCore.Server.Kestrel.Core version 2.3.0 or earlier.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-packages&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected Packages
The vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below&lt;/p&gt;
&lt;p&gt;Package name | Affected version | Patched versio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5rrx-jjjq-q2r5</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-55315 — ASP.NET Security Feature Bypass Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-55315</link>
      <description>msrc_CVE-2025-55315</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-55315</guid>
    </item>
    <item>
      <title>RHBA-2025:20916 — Red Hat Bug Fix Advisory: .NET 10.0 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:20916</link>
      <description>&lt;p&gt;dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:20916</guid>
    </item>
    <item>
      <title>RHBA-2025:20993 — Red Hat Bug Fix Advisory: .NET 10.0 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:20993</link>
      <description>&lt;p&gt;dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:20993</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-55315</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55315</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet10, Ubuntu:24.04:LTS: dotnet8, Ubuntu:25.10: dotnet10, Ubuntu:25.10: dotnet8, Ubuntu:25.10: dotnet9, Ubuntu:26.04:LTS: dotnet10&lt;/p&gt;
&lt;p&gt;Inconsistent interpretation of http requests (&amp;#39;http request/response smuggling&amp;#39;) in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet10, Ubuntu:24.04:LTS: dotnet8, Ubuntu:25.10: dotnet10, Ubuntu:25.10: dotnet8, Ubuntu:25.10: dotnet9, Ubuntu:26.04:LTS: dotnet10&lt;/p&gt;
&lt;p&gt;Inconsistent interpretation of http requests (&amp;#39;http request/response smuggling&amp;#39;) in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55315</guid>
    </item>
    <item>
      <title>VDE-2026-001 — METTLER TOLEDO: ASP.NET core vulnerability in LabX</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-001</link>
      <description>&lt;p&gt;LabX 21.2.12 (formerly known as LabX Cloud 1.2.12) is affected by the ASP.NET core vulnerability CVE-2025-55315.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LabX 21.2.12 (formerly known as LabX Cloud 1.2.12) is affected by the ASP.NET core vulnerability CVE-2025-55315.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-001</guid>
    </item>
    <item>
      <title>VDE-2026-010 — WAGO: Multiple Vulnerabilities in WAGO Solution Builder and WAGO Device Sphere</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-010</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in WAGO Solution Builder and WAGO Device Sphere that affect components responsible for authentication and system communication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in WAGO Solution Builder and WAGO Device Sphere that affect components responsible for authentication and system communication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-010</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2278 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2278</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, .NET Framework, Windows Server, ASP.NET, PowerShell und Windows ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, .NET Framework, Windows Server, ASP.NET, PowerShell und Windows ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2278</guid>
    </item>
  </channel>
</rss>
