{"id":"CVE-2020-1045","aliases":["BIT-aspnet-core-2020-1045","GHSA-hxrm-9w7p-39cc"],"url":"https://o3.security/vulnerability/CVE-2020-1045","summary":"Cookie parsing failure","details":"<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p>\n<p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p>\n<p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>","published":"2020-09-11T17:15:18.307Z","modified":"2026-07-08T05:53:31.651458579Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.05974,"percentile":0.92809,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.Http","fixedVersion":"2.1.22"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App","fixedVersion":"2.1.22"},{"ecosystem":"NuGet","name":"Microsoft.Owin","fixedVersion":"4.1.1"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.linux-arm","fixedVersion":"3.1.8"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.linux-arm64","fixedVersion":"3.1.8"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.linux-musl-x64","fixedVersion":"3.1.8"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.linux-x64","fixedVersion":"3.1.8"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.osx-x64","fixedVersion":"3.1.8"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.win-arm","fixedVersion":"3.1.8"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.win-x64","fixedVersion":"3.1.8"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.win-x86","fixedVersion":"3.1.8"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.linux-musl-arm64","fixedVersion":"3.1.8"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.App.Runtime.win-arm64","fixedVersion":"3.1.8"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:3699"},{"type":"ADVISORY","url":"https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.8/3.1.8.md#changes-in-318"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-RHEL8-DOTNET-1439600"},{"type":"FIX","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1045"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:53:31.651458579Z"}}