Flaw in Kestrel web server allowed request smuggling, impact depends on hosting setup and application code

Microsoft has patched an ASP.NET Core vulnerability with a CVSS score of 9.9, which security program manager Barry Dorrans said was “our highest ever.” The flaw is in the Kestrel web server component and enables security bypass.…