github DuendeSoftware/products aaj-1.0.2
Duende.AspNetCore.Authentication.JwtBearer 1.0.2

latest release: dmcp-0.4.0
4 hours ago

This is a patch release that fixes a thread-safety bug in DPoP proof validation.

What's Changed

Bug Fix: Fixed a race condition in DPoPProofValidator.ValidateToken() where the shared TokenValidationParameters singleton had its IssuerSigningKey overwritten by concurrent requests using different DPoP keys, causing intermittent IDX10503 signature validation failures (~5-10% failure rate under load with multiple DPoP keys).

The fix clones TokenValidationParameters before mutation so each request operates on its own copy.

Don't miss a new products release

NewReleases is sending notifications on new releases.