Download Latest Version Duende.BFF 4.3.1 source code.zip (22.4 MB) Google Add to Preferred Sources
Home / bff-3.1.1
Name Modified Size InfoDownloads / Week
Parent folder
Duende.BFF 3.1.1 source code.tar.gz 2026-10-07 24.6 MB
Duende.BFF 3.1.1 source code.zip 2026-10-07 26.6 MB
README.md 2026-10-07 1.5 kB
Totals: 3 Items   51.2 MB 0

Duende.BFF 3.1.1

This is a security patch release. It fixes a vulnerability in Duende.BFF.Yarp. We recommend that all users of the YARP integration upgrade.

The fix changes default behavior. Read Breaking changes below before you upgrade.

The same fix is released in 3.1.1, 3.0.1, 2.3.1 and 2.2.1, and for 4.x in 4.3.1, 4.2.1, 4.1.3 and 4.0.4.

Security fixes

  • The YARP integration no longer forwards the Cookie header (GHSA-vvg7-p7jw-8qr3). Routes proxied through the BFF's YARP integration (AddReverseProxy().AddBffExtensions()) forwarded the incoming Cookie header to the remote API. That header includes the BFF session cookie, which was sent along with the access token. The BFF now removes the Cookie header from requests on all YARP routes, as MapRemoteBffApiEndpoint already did.

Breaking changes

  • YARP routes no longer forward cookies to remote APIs. If an upstream API needs cookies from the browser, you can turn this off for the whole application with the new BffOptions.RemoveCookieHeaderFromYarpRequests option:

csharp builder.Services.AddBff(options => { options.RemoveCookieHeaderFromYarpRequests = false; });

With the option set to false, YARP forwards cookies as before. You can then control cookie forwarding per route with standard YARP transforms, for example RequestHeaderRemove: Cookie. Only do this for upstream APIs you trust with the BFF session cookie.

Source: README.md, updated 2026-10-07