Includes types that provide support for SignedHttpRequest protocol.
99%
Total Score
100
91
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11132 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. Microsoft.IdentityModel.Protocols.SignedHttpRequest is vulnerable to Server-Side Request Forgery (SSRF) in versions 7.1.2 - 7.7.1 and 8.0.0 - 8.18.0. | 7.1.2 - 7.7.18.0.0 - 8.18.0 | High |
CVE-2024-21643 Microsoft.IdentityModel.Protocols.SignedHttpRequest is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 6.34.0 and 7.0.0-preview - 7.1.2. | 0.0.0 - 6.34.07.0.0-preview - 7.1.2 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
microsoft.identitymodel.jsonwebtokens Version [8.22.0, ) | — | — |
microsoft.identitymodel.protocols Version [8.22.0, ) | — | — |
system.text.json Version [8.0.5, ) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.