highCVSS 7.5Vulnerability

GHSA-8fh9-c4jq-94h4

# idunno.Bluesky, idunno.AtProto and idunno.AtProto.OAuthCallback Denial of Service Vulnerability ## Impact The `Microsoft.Bcl.Memory` package, a transitive dependency of `idunno.AtProto` and `idunno.AtProto.OAuthCallback` had a Denial of Service security vulnerability, [CVE-2026-26127](https://github.com/dotnet/announcements/issues/384) ## Patches v1.7.0 updates the dependencies on `Duende.IdentityModel.OidcClient` and `Duende.IdentityModel.OidcClient.Extensions` which, in turn, updates their dependency on `Microsoft.Bcl.Memory` to 10.0.4, resolving the vulnerability. ## Workarounds No workarounds exist for this vulnerability. ## How to fix the issue To update your dependencies on `idunno.Bluesky`, `idunno.AtProto` and `idunno.AtProto.OAuthCallback`, ### Using the .NET CLI (Command Line Interface): * Open a terminal or command prompt in your project's directory. * To update a specific package to its latest version, use the following add package command: * If you are using `idunno.Bluesky` `dotnet package update idunno.Bluesky` * If you are using `idunno.AtProto` as a direct dependency `dotnet package update idunno.AtProto` * If you are using `idunno.AtProto.OAuthCallback` as a direct dependency `dotnet package update idunno.AtProto.OAuthCallback` ### Using the NuGet Package Manager Console in Visual Studio: * Open your project in Visual Studio. * Navigate to "Tools > NuGet Package Manager > Package Manager Console". * To update a specific package to its latest version, use the following Update-Package command: * If you are using `idunno.Bluesky` `Update-Package -Id idunno.Bluesky` * If you are using `idunno.AtProto` as a direct dependency `Update-Package -Id idunno.AtProto` * If you are using `idunno.AtProto.OAuthCallback` as a direct dependency `Update-Package -Id idunno.AtProto.OAuthCallback` ### NuGet Package Manager UI in Visual Studio: * Open your project in Visual Studio. * Right-click on your projec

Properties

ghsa_id
GHSA-8fh9-c4jq-94h4
severity
high
summary
idunno.Bluesky, idunno.AtProto and idunno.AtProto.OAuthCallback Denial of Service Vulnerability
cvss_score
7.5
cve_id
GHSA-8fh9-c4jq-94h4
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-03-13T20:50:22Z
source_url
https://github.com/advisories/GHSA-8fh9-c4jq-94h4
ghsa_updated
2026-03-13T20:50:25Z

Related Entities (5)

AFFECTS (3)

[Software]nuget/idunno.AtProto.OAuthCallback
[Software]nuget/idunno.AtProto
[Software]nuget/idunno.Bluesky

HAS_WEAKNESS (1)

[Weakness]Improper Validation of Array Index

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph