Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| Microsoft.AspNetCore.Server.Kestrel.Core(NuGet) | 0 | 2.3.6 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm64(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm64(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-x64(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-x64(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-arm64(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-x64(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm64(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x64(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x86(NuGet) | 10.0.0-rc.1.25451.107 | 10.0.0-rc.2.25502.107 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm64(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm64(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-x64(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-x64(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-arm64(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-x64(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm64(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x64(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x86(NuGet) | 9.0.0 | 9.0.10 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-arm64(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-arm64(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-musl-x64(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.linux-x64(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-arm64(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.osx-x64(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-arm64(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x64(NuGet) | 8.0.0 | 8.0.21 | N/A |
| Microsoft.AspNetCore.App.Runtime.win-x86(NuGet) | 8.0.0 | 8.0.21 | N/A |
CVSS Metrics