Microsoft.AspNetCore.DataProtection
ASP.NET Core logic to protect and unprotect data, similar to DPAPI. This package was built from the source code at https://github.com/dotnet/dotnet/tree/3551975be08744f0418857c5bed8ab1545c5dd47
Activity
- Latest release
- 5d ago
- Total releases
- 277
- Cadence
- ~daily
- Last 12 months
- 49
Details
- License
- MIT
- First release
- May 16, 2016
| Version | Released | |
|---|---|---|
2.3.13
patch
|
2.3.13
patch
Dependencies (9)
+ 1 more |
|
9.0.20
patch
|
9.0.20
patch
Dependencies (10)
+ 2 more |
|
10.0.12
patch
|
10.0.12
patch
Dependencies (10)
+ 2 more |
|
8.0.31
patch
|
8.0.31
patch
Dependencies (10)
+ 2 more |
|
11.0.0-rc.1.26425.128
pre
|
11.0.0-rc.1.26425.128
pre
Dependencies (10)
+ 2 more |
|
2.3.12
patch
|
2.3.12
patch
Dependencies (9)
+ 1 more |
|
9.0.19
patch
|
9.0.19
patch
Dependencies (10)
+ 2 more |
|
10.0.11
patch
|
10.0.11
patch
Dependencies (10)
+ 2 more |
|
8.0.30
patch
|
8.0.30
patch
Dependencies (10)
+ 2 more |
|
11.0.0-preview.7.26381.103
pre
|
11.0.0-preview.7.26381.103
pre
Dependencies (10)
+ 2 more |
|
9.0.18
patch
|
9.0.18
patch
Dependencies (10)
+ 2 more |
|
10.0.10
patch
|
10.0.10
patch
Dependencies (10)
+ 2 more |
|
8.0.29
patch
|
8.0.29
patch
Dependencies (10)
+ 2 more |
|
11.0.0-preview.6.26359.118
pre
|
11.0.0-preview.6.26359.118
pre
Dependencies (10)
+ 2 more |
|
2.3.11
patch
|
2.3.11
patch
Dependencies (9)
+ 1 more |
|
9.0.17
patch
|
9.0.17
patch
Dependencies (10)
+ 2 more |
|
10.0.9
patch
|
10.0.9
patch
Dependencies (10)
+ 2 more |
|
8.0.28
patch
|
8.0.28
patch
Dependencies (10)
+ 2 more |
|
11.0.0-preview.5.26302.115
pre
|
11.0.0-preview.5.26302.115
pre
Dependencies (10)
+ 2 more |
|
2.3.10
patch
|
2.3.10
patch
Dependencies (9)
+ 1 more |
|
9.0.16
patch
|
9.0.16
patch
Dependencies (10)
+ 2 more |
|
10.0.8
patch
|
10.0.8
patch
Dependencies (10)
+ 2 more |
|
8.0.27
patch
|
8.0.27
patch
Dependencies (10)
+ 2 more |
|
11.0.0-preview.4.26230.115
pre
|
11.0.0-preview.4.26230.115
pre
Dependencies (10)
+ 2 more |
|
10.0.7
patch
|
10.0.7
patch
Dependencies (10)
+ 2 more |
|
9.0.15
patch
|
9.0.15
patch
Dependencies (10)
+ 2 more |
|
8.0.26
patch
|
8.0.26
patch
Dependencies (10)
+ 2 more |
|
11.0.0-preview.3.26207.106
pre
|
11.0.0-preview.3.26207.106
pre
Dependencies (10)
+ 2 more |
|
10.0.5
patch
1 CVE
CVE-2026-40372
GHSA-9mv3-2cwr-p262
BIT-aspnet-core-2026-40372
Apr 23, 2026
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
Executive Summary:A bug in If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves. Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated. This is comparable in capability to MS10-070, which exploited a similar padding-oracle condition in ASP.NET's legacy encryption infrastructure. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/395 CVSS Details
Affected Platforms
Affected PackagesThe vulnerability affects some Microsoft .NET projects if they use any of affected package versions listed below ASP.NET Core 10Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.DataProtection | >=10.0.0, <=10.0.6 | 10.0.7 Advisory FAQHow do I know if I am affected?Primary affected configuration (10.0.6 on
|
10.0.5
patch
Dependencies (10)
+ 2 more |
|
11.0.0-preview.2.26159.112
pre
|
11.0.0-preview.2.26159.112
pre
Dependencies (10)
+ 2 more |
|
9.0.14
patch
|
9.0.14
patch
Dependencies (10)
+ 2 more |
|
8.0.25
patch
|
8.0.25
patch
Dependencies (10)
+ 2 more |
|
10.0.4
patch
1 CVE
CVE-2026-40372
GHSA-9mv3-2cwr-p262
BIT-aspnet-core-2026-40372
Apr 23, 2026
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
Executive Summary:A bug in If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves. Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated. This is comparable in capability to MS10-070, which exploited a similar padding-oracle condition in ASP.NET's legacy encryption infrastructure. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/395 CVSS Details
Affected Platforms
Affected PackagesThe vulnerability affects some Microsoft .NET projects if they use any of affected package versions listed below ASP.NET Core 10Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.DataProtection | >=10.0.0, <=10.0.6 | 10.0.7 Advisory FAQHow do I know if I am affected?Primary affected configuration (10.0.6 on
|
10.0.4
patch
Dependencies (10)
+ 2 more |
|
11.0.0-preview.1.26104.118
pre
|
11.0.0-preview.1.26104.118
pre
Dependencies (10)
+ 2 more |
|
9.0.13
patch
|
9.0.13
patch
Dependencies (10)
+ 2 more |
|
10.0.3
patch
1 CVE
CVE-2026-40372
GHSA-9mv3-2cwr-p262
BIT-aspnet-core-2026-40372
Apr 23, 2026
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
Executive Summary:A bug in If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves. Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated. This is comparable in capability to MS10-070, which exploited a similar padding-oracle condition in ASP.NET's legacy encryption infrastructure. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/395 CVSS Details
Affected Platforms
Affected PackagesThe vulnerability affects some Microsoft .NET projects if they use any of affected package versions listed below ASP.NET Core 10Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.DataProtection | >=10.0.0, <=10.0.6 | 10.0.7 Advisory FAQHow do I know if I am affected?Primary affected configuration (10.0.6 on
|
10.0.3
patch
Dependencies (10)
+ 2 more |
|
8.0.24
patch
|
8.0.24
patch
Dependencies (10)
+ 2 more |
|
9.0.12
patch
|
9.0.12
patch
Dependencies (10)
+ 2 more |
|
10.0.2
patch
1 CVE
CVE-2026-40372
GHSA-9mv3-2cwr-p262
BIT-aspnet-core-2026-40372
Apr 23, 2026
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
Executive Summary:A bug in If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves. Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated. This is comparable in capability to MS10-070, which exploited a similar padding-oracle condition in ASP.NET's legacy encryption infrastructure. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/395 CVSS Details
Affected Platforms
Affected PackagesThe vulnerability affects some Microsoft .NET projects if they use any of affected package versions listed below ASP.NET Core 10Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.DataProtection | >=10.0.0, <=10.0.6 | 10.0.7 Advisory FAQHow do I know if I am affected?Primary affected configuration (10.0.6 on
|
10.0.2
patch
Dependencies (10)
+ 2 more |
|
8.0.23
patch
|
8.0.23
patch
Dependencies (10)
+ 2 more |
|
2.3.9
patch
|
2.3.9
patch
Dependencies (9)
+ 1 more |
|
2.3.8
patch
|
2.3.8
patch
Dependencies (9)
+ 1 more |
|
10.0.1
patch
1 CVE
CVE-2026-40372
GHSA-9mv3-2cwr-p262
BIT-aspnet-core-2026-40372
Apr 23, 2026
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
Executive Summary:A bug in If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves. Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated. This is comparable in capability to MS10-070, which exploited a similar padding-oracle condition in ASP.NET's legacy encryption infrastructure. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/395 CVSS Details
Affected Platforms
Affected PackagesThe vulnerability affects some Microsoft .NET projects if they use any of affected package versions listed below ASP.NET Core 10Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.DataProtection | >=10.0.0, <=10.0.6 | 10.0.7 Advisory FAQHow do I know if I am affected?Primary affected configuration (10.0.6 on
|
10.0.1
patch
Dependencies (10)
+ 2 more |
|
10.0.0
major
1 CVE
CVE-2026-40372
GHSA-9mv3-2cwr-p262
BIT-aspnet-core-2026-40372
Apr 23, 2026
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
Executive Summary:A bug in If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves. Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated. This is comparable in capability to MS10-070, which exploited a similar padding-oracle condition in ASP.NET's legacy encryption infrastructure. AnnouncementAnnouncement for this issue can be found at https://github.com/dotnet/announcements/issues/395 CVSS Details
Affected Platforms
Affected PackagesThe vulnerability affects some Microsoft .NET projects if they use any of affected package versions listed below ASP.NET Core 10Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- Microsoft.AspNetCore.DataProtection | >=10.0.0, <=10.0.6 | 10.0.7 Advisory FAQHow do I know if I am affected?Primary affected configuration (10.0.6 on
|
10.0.0
major
Dependencies (10)
+ 2 more |
|
9.0.11
patch
|
9.0.11
patch
Dependencies (10)
+ 2 more |
|
8.0.22
patch
|
8.0.22
patch
Dependencies (10)
+ 2 more |
|
9.0.10
patch
|
9.0.10
patch
Dependencies (10)
+ 2 more |
|
8.0.21
patch
|
8.0.21
patch
Dependencies (10)
+ 2 more |
|
10.0.0-rc.2.25502.107
pre
|
10.0.0-rc.2.25502.107
pre
Dependencies (10)
+ 2 more |
|
9.0.9
patch
|
9.0.9
patch
Dependencies (10)
+ 2 more |