{"id":"GHSA-8fh9-c4jq-94h4","summary":"idunno.Bluesky, idunno.AtProto and idunno.AtProto.OAuthCallback Denial of Service Vulnerability","details":"# idunno.Bluesky, idunno.AtProto and idunno.AtProto.OAuthCallback Denial of Service Vulnerability\n\n## Impact\n\nThe `Microsoft.Bcl.Memory` package, a transitive dependency of `idunno.AtProto` and `idunno.AtProto.OAuthCallback` had a Denial of Service security vulnerability, [CVE-2026-26127](https://github.com/dotnet/announcements/issues/384)\n\n## Patches\n\nv1.7.0 updates the dependencies on `Duende.IdentityModel.OidcClient` and `Duende.IdentityModel.OidcClient.Extensions` which, in turn, updates their dependency on `Microsoft.Bcl.Memory` to 10.0.4, resolving the vulnerability.\n\n## Workarounds\n\nNo workarounds exist for this vulnerability.\n\n## How to fix the issue\n\nTo update your dependencies on `idunno.Bluesky`, `idunno.AtProto` and `idunno.AtProto.OAuthCallback`, \n\n### Using the .NET CLI (Command Line Interface):\n\n* Open a terminal or command prompt in your project's directory.\n* To update a specific package to its latest version, use the following add package command:\n   \n  * If you are using `idunno.Bluesky`\n    `dotnet package update idunno.Bluesky`\n\n  * If you are using `idunno.AtProto` as a direct dependency\n    `dotnet package update idunno.AtProto`\n\n  * If you are using `idunno.AtProto.OAuthCallback` as a direct dependency\n    `dotnet package update idunno.AtProto.OAuthCallback`\n\n### Using the NuGet Package Manager Console in Visual Studio:\n\n* Open your project in Visual Studio.\n* Navigate to \"Tools \u003e NuGet Package Manager \u003e Package Manager Console\".\n* To update a specific package to its latest version, use the following Update-Package command:\n\n  * If you are using `idunno.Bluesky`\n    `Update-Package -Id idunno.Bluesky`\n\n  * If you are using `idunno.AtProto` as a direct dependency\n    `Update-Package -Id idunno.AtProto`\n\n  * If you are using `idunno.AtProto.OAuthCallback` as a direct dependency\n    `Update-Package -Id idunno.AtProto.OAuthCallback`\n\n### NuGet Package Manager UI in Visual Studio:\n\n* Open your project in Visual Studio.\n* Right-click on your project in Solution Explorer and select \"Manage NuGet Packages...\" or navigate to \"Project \u003e Manage NuGet Packages\".\n* In the NuGet Package Manager window, select the \"Updates\" tab. This tab lists packages with available updates from your configured package sources.\n* Select the package(s) you wish to update. You can choose a specific version from the dropdown or update to the latest available version.\n* Click the \"Update\" button.\n\n## References\n\n*  [Microsoft Security Advisory CVE-2026-26127 – .NET Denial of Service Vulnerability](https://github.com/dotnet/announcements/issues/384)\n*  [CVE-2026-26127](https://www.cve.org/CVERecord?id=CVE-2026-26127)","modified":"2026-03-13T22:14:44.650695Z","published":"2026-03-13T20:50:22Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-03-13T20:50:22Z","nvd_published_at":null,"cwe_ids":["CWE-129"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/blowdart/idunno.Bluesky/security/advisories/GHSA-8fh9-c4jq-94h4"},{"type":"WEB","url":"https://github.com/dotnet/announcements/issues/384"},{"type":"PACKAGE","url":"https://github.com/blowdart/idunno.Bluesky"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-26127"}],"affected":[{"package":{"name":"idunno.AtProto","ecosystem":"NuGet","purl":"pkg:nuget/idunno.AtProto"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.0"}]}],"versions":["0.1.0-prerelease","0.1.1-prerelease","0.1.2-prerelease","0.1.3-prerelease","0.2.0-prerelease","0.2.1-prerelease","0.3.0-prerelease","0.4.0-prerelease","0.4.1-prerelease","0.5.0-prerelease","0.6.0-prerelease","0.6.1-prerelease","0.7.0-prerelease","0.8.0-prerelease","0.9.0-prerelease","0.9.1-prerelease","0.9.2-prerelease","0.9.3-prerelease","0.9.4-prerelease","0.9.5-prerelease","0.9.7-prerelease","0.9.8-prerelease","0.9.9-prerelease","1.0.0","1.1.0","1.1.0-prerelease","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-8fh9-c4jq-94h4/GHSA-8fh9-c4jq-94h4.json"}},{"package":{"name":"idunno.AtProto.OAuthCallback","ecosystem":"NuGet","purl":"pkg:nuget/idunno.AtProto.OAuthCallback"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.0"}]}],"versions":["0.3.0-prerelease","0.4.0-prerelease","0.4.1-prerelease","0.5.0-prerelease","0.6.0-prerelease","0.6.1-prerelease","0.7.0-prerelease","0.8.0-prerelease","0.9.0-prerelease","0.9.1-prerelease","0.9.2-prerelease","0.9.3-prerelease","0.9.4-prerelease","0.9.5-prerelease","0.9.7-prerelease","0.9.8-prerelease","0.9.9-prerelease","1.0.0","1.1.0","1.1.0-prerelease","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-8fh9-c4jq-94h4/GHSA-8fh9-c4jq-94h4.json"}},{"package":{"name":"idunno.Bluesky","ecosystem":"NuGet","purl":"pkg:nuget/idunno.Bluesky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.0"}]}],"versions":["0.1.0-prerelease","0.1.1-prerelease","0.1.2-prerelease","0.1.3-prerelease","0.2.0-prerelease","0.2.1-prerelease","0.3.0-prerelease","0.4.0-prerelease","0.4.1-prerelease","0.5.0-prerelease","0.6.0-prerelease","0.6.1-prerelease","0.7.0-prerelease","0.8.0-prerelease","0.9.0-prerelease","0.9.1-prerelease","0.9.2-prerelease","0.9.3-prerelease","0.9.4-prerelease","0.9.5-prerelease","0.9.7-prerelease","0.9.8-prerelease","0.9.9-prerelease","1.0.0","1.1.0","1.1.0-prerelease","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-8fh9-c4jq-94h4/GHSA-8fh9-c4jq-94h4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}