critical
CVE-2025-55315
Kestrel HTTP request smuggling security-feature bypass
- Severity
- critical
- Affected product
- Kestrel
- Affected versions
- Kestrel ≥ 8.0.0, < 8.0.21
- Affected versions
- Kestrel ≥ 9.0.0, < 9.0.10
- Affected versions
- Kestrel ≤ 2.3.0
- Fixed in
- Kestrel 8.0.21
- Fixed in
- Kestrel 9.0.10
- Fixed in
- Kestrel 2.3.6
- Added to NewScan
- 2026-08-19
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Kestrel from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints Kestrel from its response and reports this CVE when the detected version falls inside the affected range below.
COMPONENT VERSION RANGE
NewScan fingerprints Kestrel from its response and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →