Microsoft.IdentityModel.Protocols.SignedHttpRequest is vulnerable to Server-Side Request Forgery (SSRF)
82
High Risk
The SignedHttpRequest handler validates jku claim URLs against an operator-defined domain allowlist before fetching JSON Web Key Sets. Before the fix, allowlist matching used permissive suffix checks so unrelated hosts such as wrongcontoso.com or arbitrary .com sites could match entries intended for contoso.com. When jku resolution is enabled, an attacker can steer the handler toward an attacker-controlled endpoint and supply signing material that influences PoP key validation. The fix requires exact host matches or proper dot-bounded subdomain matches.
You are affected if you are using a version that falls within the vulnerable range.
Microsoft.IdentityModel.Protocols.SignedHttpRequest is vulnerable to Server-Side Request Forgery (SSRF) in versions 7.1.2 - 7.7.1 and 8.0.0 - 8.18.0.
Upgrade the Microsoft.IdentityModel.Protocols.SignedHttpRequest library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant