惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
博客园 - 聂微东
博客园_首页
人人都是产品经理
人人都是产品经理
N
News | PayPal Newsroom
云风的 BLOG
云风的 BLOG
U
Unit 42
T
Tailwind CSS Blog
Recent Announcements
Recent Announcements
Security Archives - TechRepublic
Security Archives - TechRepublic
T
The Blog of Author Tim Ferriss
Stack Overflow Blog
Stack Overflow Blog
The Register - Security
The Register - Security
The Hacker News
The Hacker News
博客园 - Franky
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
F
Fortinet All Blogs
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Check Point Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
有赞技术团队
有赞技术团队
TaoSecurity Blog
TaoSecurity Blog
博客园 - 司徒正美
GbyAI
GbyAI
G
Google Developers Blog
B
Blog
G
GRAHAM CLULEY
Y
Y Combinator Blog
雷峰网
雷峰网
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
V
V2EX
罗磊的独立博客
Know Your Adversary
Know Your Adversary
AWS News Blog
AWS News Blog
T
Troy Hunt's Blog
S
SegmentFault 最新的问题
P
Privacy & Cybersecurity Law Blog
T
Threat Research - Cisco Blogs
H
Help Net Security
N
Netflix TechBlog - Medium
Help Net Security
Help Net Security
L
LangChain Blog
D
Docker

Duende Software Official Site

Duende Software Duende Software Duende Software Duende Software Duende Software Stop AI Bots from Wasting Your Server How Duende IdentityServer Filters Claims (And Why It Matters) Core vs Extended Protocols in Duende IdentityServer v8: What You Get and When You Need More Your IdentityServer v8 Upgrade Checklist: A Quick Pre-Flight Guide Setting Up SAML Single Sign-On in ASP.NET with Duende IdentityServer Your Identity, Your Terms: Duende's Modular Identity Infrastructure and v8.x Release Duende Spring Launch '26: Identity Infrastructure That Expands With You SAML and OpenID Connect (OIDC): Coexistence, Not Competition The 9 Components of SAML You Need to Know, Ranked by Importance The Cost of NOT Implementing Financial-Grade Security Token Issuer Isolation: Why It Matters for Security and Compliance The Composable Identity Pattern: Build What You Need, Skip What You Don't Multi-Brand Identity: When Your Company Needs More Than One Face Post-Quantum Cryptography in .NET 10: A Practical Guide The field Keyword in C# 14: Write Less, Validate More The Real Cost of Build vs. Buy for Identity OAuth 2.1 Made Simple: The Only Flows You Need Beyond localhost: Multi-Instance ASP.NET Core Deployment with .NET 10 Harden Your .NET JSON Deserialization with System.Text.Json and JsonSerializerOptions.Strict ASP.NET Core Cookie Size Limits in Production: Causes and Fixes The Emergency Stop Button - Implementing Immediate Token Revocation in .NET 10 The 2025 OWASP Top 10 and IdentityServer Update Guidance for CVE-2026-40372 - ASP.NET Data Protection Why a Standard JWT Access Token Matters The Identity Governance Checklist You Wish You Had Six Months Ago The History and Future of SAML: Why a 20-Year-Old Protocol Still Matters The Cookie Apocalypse Already Happened Verify - Open Source Sponsorship Why Identity Is Infrastructure, Not a Feature Extending Duende IdentityServer Server-Side Sessions with Dynamic User Metadata Give Your AI Coding Assistant Duende Expertise with Agent Skills and MCP Server Triggering User Registration via OpenID Connect with Duende IdentityServer Improving .NET Security Code with C# 14 Property Extensions Developing Audit Logs with Duende IdentityServer Events Patch Releases: Addressing CVE-2026-26127 in Microsoft.BCL.Memory Client-Initiated Backchannel Authentication (CIBA) in ASP.NET Core 10 with Duende Identity Server Rate Limiting IdentityServer Endpoints It's Probably DNS - Can You Dig It? Security Lingo Explained: Encode vs Encrypt vs Hash Implementing Zero Trust with Resource Isolation Security Lingo Explained: JWT DPoP Security for .NET APIs with JwtBearer Extensions v1.0.0 Announcing the Duende IdentityServer4 Migration Analysis Tool BenchmarkDotNet - Open Source Sponsorship Security Lingo Explained: PAR Why Signing Key Rotation Matters in OpenID Connect and Duende IdentityServer Security Lingo Explained: OP Duende Year-End Review 2025 Security Lingo Explained: BCP Security Lingo Explained: DPoP Security Lingo Explained: Auth Secure frontend apps with the BFF Pattern Scaling with Duende IdentityServer, MCP, and AI Duende IdentityServer v7.4 is now available Duende BFFv4 is now available Securing OpenAPI and Swagger UI with OAuth in .NET 10 Building a Federation Gateway with Duende IdentityServer: Strategies and Considerations for Identity Orchestration
Duende Software
Damian Hickey · 2026-07-15 · via Duende Software Official Site

On July 14, 2026, Microsoft released the .NET July 2026 security updates, shipping .NET 10.0.10, 9.0.18, and 8.0.29. This is a big one: 17 security advisories in a single Patch Tuesday, covering the runtime, ASP.NET Core, and the SDK.

We've reviewed every advisory against our products. The short version: no Duende packages are affected, and no Duende patch releases are required. The fixes all live in the .NET runtime and shared framework, so you get them by updating your .NET installation. Here's what you need to know.

What Microsoft Fixed

The July updates address vulnerabilities across several areas. The ones most relevant to identity and access management workloads:

The remaining advisories cover SignalR stateful reconnect, the SMTP client, WPF XAML parsing, and the SDK container build process. The full list is in the dotnet/announcements repository.

How This Affects Duende Products

We checked every affected package against IdentityServer, BFF, and the rest of our library stack, including all supported release lines.

The good news: nothing changes in our packages. Unlike the Microsoft.BCL.Memory issue earlier this year, none of the vulnerable components are NuGet dependencies of our published packages. They are part of the .NET runtime and the ASP.NET Core shared framework, which your application picks up from the .NET installation on the machine. Updating your runtime updates the vulnerable code, with no package changes needed from us or from you.

A few areas deserve a closer look, so here's what we verified:

IdentityServer and XML encryption. IdentityServer 8.x uses EncryptedXml in its SAML support to decrypt SAML assertions. We reviewed the July fixes in detail against our code. The patched logic (transform validation and recursion depth limits in XML parsing) runs entirely in the shared framework, and our code builds on top of it rather than reimplementing it. Once your host runs .NET 10.0.10, IdentityServer's SAML processing is protected. IdentityServer 7.x does not include SAML support and doesn't use EncryptedXml at all.

TLS, X.509, and HTTP/2 fixes. If your IdentityServer host terminates TLS directly, all three apply to you. If you sit behind a reverse proxy or load balancer that terminates TLS, your exposure is smaller but not zero. The X.509 parsing fix matters either way: IdentityServer parses certificates from sources other than the TLS handshake, such as x5c headers in client assertions, JWKS documents, SAML metadata, and client certificates forwarded by your proxy in mTLS setups. The TLS fixes also cover outbound connections your host makes (backchannel calls, JWKS retrieval), and the HTTP/2 fix applies if the proxy-to-app hop uses HTTP/2, or if the proxy itself runs on .NET, as with YARP or Duende BFF. In every case the fix ships with the runtime, so updating your .NET installation (or your base container images) is what closes them.

Negotiate and SignalR advisories. These only apply if your own application uses Negotiate authentication with LDAP role retrieval, or SignalR with stateful reconnect. Duende products don't use either.

What Should You Do?

Update your .NET runtime. Install the July 2026 servicing release for the version you run:

Runtime Patched version

.NET 10

10.0.10 (SDK 10.0.302)

.NET 9

9.0.18 (SDK 9.0.316)

.NET 8

8.0.29 (SDK 8.0.129)

Downloads and release notes are available on the .NET download pages.

Rebuild and redeploy your containers. If you deploy with Docker, update your mcr.microsoft.com/dotnet/aspnet base images to the July releases and rebuild. If you pin base images by digest (a good supply chain practice), update the pin to the digest of the patched image. If you use floating tags, make sure your build actually pulls the new image rather than reusing a cached layer.

Update your build agents. The SDK updates also fix a container image build tampering issue (CVE-2026-50526), so update the SDK on CI machines too, especially shared build servers.

That's it. No Duende package updates to install, no configuration changes, no workarounds.

A Note on Behavior Changes

The EncryptedXml fixes tighten what the parser accepts: CipherReference transforms are now restricted to a built-in allowlist, and deeply nested encrypted XML structures are rejected. Legitimate SAML traffic is unaffected, since standard SAML encryption uses none of the newly blocked constructs. Microsoft provides AppContext switches to restore the old behavior if you run into an edge case, but we recommend leaving the new defaults in place.

If you have questions about your specific deployment, reach out through the Duende support channels. And as always: keep your runtimes patched. Most of the fixes in this round protect you at the host level, below any application code.