惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
T
The Exploit Database - CXSecurity.com
V
Vulnerabilities – Threatpost
Know Your Adversary
Know Your Adversary
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
N
News and Events Feed by Topic
Spread Privacy
Spread Privacy
Application and Cybersecurity Blog
Application and Cybersecurity Blog
S
Secure Thoughts
G
GRAHAM CLULEY
Google Online Security Blog
Google Online Security Blog
Help Net Security
Help Net Security
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
O
OpenAI News
Google DeepMind News
Google DeepMind News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Security Archives - TechRepublic
Security Archives - TechRepublic
L
LINUX DO - 最新话题
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Stack Overflow Blog
Stack Overflow Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
Lohrmann on Cybersecurity
H
Hacker News: Front Page
W
WeLiveSecurity
P
Privacy International News Feed
Forbes - Security
Forbes - Security
月光博客
月光博客
PCI Perspectives
PCI Perspectives
T
Tailwind CSS Blog
N
News and Events Feed by Topic
T
Threat Research - Cisco Blogs
Engineering at Meta
Engineering at Meta
F
Full Disclosure
AI
AI
Hacker News - Newest:
Hacker News - Newest: "LLM"
Schneier on Security
Schneier on Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Darknet – Hacking Tools, Hacker News & Cyber Security
V
Visual Studio Blog
The Hacker News
The Hacker News
博客园 - 叶小钗
G
Google Developers Blog
Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
T
The Blog of Author Tim Ferriss

Duende Software Official Site

Duende Software Duende Software Duende Software Duende Software Duende Software Stop AI Bots from Wasting Your Server How Duende IdentityServer Filters Claims (And Why It Matters) Core vs Extended Protocols in Duende IdentityServer v8: What You Get and When You Need More Your IdentityServer v8 Upgrade Checklist: A Quick Pre-Flight Guide Setting Up SAML Single Sign-On in ASP.NET with Duende IdentityServer Your Identity, Your Terms: Duende's Modular Identity Infrastructure and v8.x Release Duende Spring Launch '26: Identity Infrastructure That Expands With You SAML and OpenID Connect (OIDC): Coexistence, Not Competition The 9 Components of SAML You Need to Know, Ranked by Importance The Cost of NOT Implementing Financial-Grade Security Token Issuer Isolation: Why It Matters for Security and Compliance The Composable Identity Pattern: Build What You Need, Skip What You Don't Multi-Brand Identity: When Your Company Needs More Than One Face Post-Quantum Cryptography in .NET 10: A Practical Guide The field Keyword in C# 14: Write Less, Validate More The Real Cost of Build vs. Buy for Identity OAuth 2.1 Made Simple: The Only Flows You Need Beyond localhost: Multi-Instance ASP.NET Core Deployment with .NET 10 Harden Your .NET JSON Deserialization with System.Text.Json and JsonSerializerOptions.Strict ASP.NET Core Cookie Size Limits in Production: Causes and Fixes The Emergency Stop Button - Implementing Immediate Token Revocation in .NET 10 The 2025 OWASP Top 10 and IdentityServer Update Guidance for CVE-2026-40372 - ASP.NET Data Protection Why a Standard JWT Access Token Matters The Identity Governance Checklist You Wish You Had Six Months Ago The History and Future of SAML: Why a 20-Year-Old Protocol Still Matters The Cookie Apocalypse Already Happened Verify - Open Source Sponsorship Why Identity Is Infrastructure, Not a Feature Extending Duende IdentityServer Server-Side Sessions with Dynamic User Metadata Give Your AI Coding Assistant Duende Expertise with Agent Skills and MCP Server Triggering User Registration via OpenID Connect with Duende IdentityServer Improving .NET Security Code with C# 14 Property Extensions Developing Audit Logs with Duende IdentityServer Events Patch Releases: Addressing CVE-2026-26127 in Microsoft.BCL.Memory Client-Initiated Backchannel Authentication (CIBA) in ASP.NET Core 10 with Duende Identity Server Rate Limiting IdentityServer Endpoints It's Probably DNS - Can You Dig It? Security Lingo Explained: Encode vs Encrypt vs Hash Implementing Zero Trust with Resource Isolation Security Lingo Explained: JWT DPoP Security for .NET APIs with JwtBearer Extensions v1.0.0 Announcing the Duende IdentityServer4 Migration Analysis Tool BenchmarkDotNet - Open Source Sponsorship Security Lingo Explained: PAR Why Signing Key Rotation Matters in OpenID Connect and Duende IdentityServer Security Lingo Explained: OP Duende Year-End Review 2025 Security Lingo Explained: BCP Security Lingo Explained: DPoP Security Lingo Explained: Auth Secure frontend apps with the BFF Pattern Scaling with Duende IdentityServer, MCP, and AI Duende IdentityServer v7.4 is now available Duende BFFv4 is now available Securing OpenAPI and Swagger UI with OAuth in .NET 10 Building a Federation Gateway with Duende IdentityServer: Strategies and Considerations for Identity Orchestration
Duende Software
Damian Hickey · 2026-07-15 · via Duende Software Official Site

On July 14, 2026, Microsoft released the .NET July 2026 security updates, shipping .NET 10.0.10, 9.0.18, and 8.0.29. This is a big one: 17 security advisories in a single Patch Tuesday, covering the runtime, ASP.NET Core, and the SDK.

We've reviewed every advisory against our products. The short version: no Duende packages are affected, and no Duende patch releases are required. The fixes all live in the .NET runtime and shared framework, so you get them by updating your .NET installation. Here's what you need to know.

What Microsoft Fixed

The July updates address vulnerabilities across several areas. The ones most relevant to identity and access management workloads:

The remaining advisories cover SignalR stateful reconnect, the SMTP client, WPF XAML parsing, and the SDK container build process. The full list is in the dotnet/announcements repository.

How This Affects Duende Products

We checked every affected package against IdentityServer, BFF, and the rest of our library stack, including all supported release lines.

The good news: nothing changes in our packages. Unlike the Microsoft.BCL.Memory issue earlier this year, none of the vulnerable components are NuGet dependencies of our published packages. They are part of the .NET runtime and the ASP.NET Core shared framework, which your application picks up from the .NET installation on the machine. Updating your runtime updates the vulnerable code, with no package changes needed from us or from you.

A few areas deserve a closer look, so here's what we verified:

IdentityServer and XML encryption. IdentityServer 8.x uses EncryptedXml in its SAML support to decrypt SAML assertions. We reviewed the July fixes in detail against our code. The patched logic (transform validation and recursion depth limits in XML parsing) runs entirely in the shared framework, and our code builds on top of it rather than reimplementing it. Once your host runs .NET 10.0.10, IdentityServer's SAML processing is protected. IdentityServer 7.x does not include SAML support and doesn't use EncryptedXml at all.

TLS, X.509, and HTTP/2 fixes. If your IdentityServer host terminates TLS directly, all three apply to you. If you sit behind a reverse proxy or load balancer that terminates TLS, your exposure is smaller but not zero. The X.509 parsing fix matters either way: IdentityServer parses certificates from sources other than the TLS handshake, such as x5c headers in client assertions, JWKS documents, SAML metadata, and client certificates forwarded by your proxy in mTLS setups. The TLS fixes also cover outbound connections your host makes (backchannel calls, JWKS retrieval), and the HTTP/2 fix applies if the proxy-to-app hop uses HTTP/2, or if the proxy itself runs on .NET, as with YARP or Duende BFF. In every case the fix ships with the runtime, so updating your .NET installation (or your base container images) is what closes them.

Negotiate and SignalR advisories. These only apply if your own application uses Negotiate authentication with LDAP role retrieval, or SignalR with stateful reconnect. Duende products don't use either.

What Should You Do?

Update your .NET runtime. Install the July 2026 servicing release for the version you run:

Runtime Patched version

.NET 10

10.0.10 (SDK 10.0.302)

.NET 9

9.0.18 (SDK 9.0.316)

.NET 8

8.0.29 (SDK 8.0.129)

Downloads and release notes are available on the .NET download pages.

Rebuild and redeploy your containers. If you deploy with Docker, update your mcr.microsoft.com/dotnet/aspnet base images to the July releases and rebuild. If you pin base images by digest (a good supply chain practice), update the pin to the digest of the patched image. If you use floating tags, make sure your build actually pulls the new image rather than reusing a cached layer.

Update your build agents. The SDK updates also fix a container image build tampering issue (CVE-2026-50526), so update the SDK on CI machines too, especially shared build servers.

That's it. No Duende package updates to install, no configuration changes, no workarounds.

A Note on Behavior Changes

The EncryptedXml fixes tighten what the parser accepts: CipherReference transforms are now restricted to a built-in allowlist, and deeply nested encrypted XML structures are rejected. Legitimate SAML traffic is unaffected, since standard SAML encryption uses none of the newly blocked constructs. Microsoft provides AppContext switches to restore the old behavior if you run into an edge case, but we recommend leaving the new defaults in place.

If you have questions about your specific deployment, reach out through the Duende support channels. And as always: keep your runtimes patched. Most of the fixes in this round protect you at the host level, below any application code.