2026-04-30
9m
CVE-2026-40372: The ASP.NET Core Data Protection Flaw That Demands More Than a Patch
A critical HMAC validation bug in Microsoft.AspNetCore.DataProtection lets attackers forge authentication cookies and decrypt protected payloads. Upgrading to 10.0.7 fixes the code, but key rotation and artifact auditing are essential to close the window fully.
2026-04-22
9m
CVE-2026-40372: The Data Protection HMAC Bug That Made Cookie Forgery Trivial on Linux
Microsoft's emergency .NET 10.0.7 out-of-band update patches a CVSS 9.1 flaw in the Data Protection managed encryptor. If you run ASP.NET Core on Linux, your HMAC validation was effectively broken since .NET 10 shipped.
2025-12-05
4m
The ASP.NET Core Data Protection API: Encrypting Data the Right Way
How ASP.NET Core's Data Protection API handles key management, encryption, and data persistence — and how to configure it for production.