← All CVEs NewScan detects
critical

CVE-2025-55315

Kestrel HTTP request smuggling security-feature bypass

Severity
critical
Affected product
Kestrel
Affected versions
Kestrel ≥ 8.0.0, < 8.0.21
Affected versions
Kestrel ≥ 9.0.0, < 9.0.10
Affected versions
Kestrel ≤ 2.3.0
Fixed in
Kestrel 8.0.21
Fixed in
Kestrel 9.0.10
Fixed in
Kestrel 2.3.6
Added to NewScan
2026-08-19
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Kestrel from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints Kestrel from its response and reports this CVE when the detected version falls inside the affected range below.

COMPONENT VERSION RANGE

NewScan fingerprints Kestrel from its response and reports this CVE when the detected version falls inside the affected range below.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →