OWASP Top 10 2025 Explained for .NET Developers
October 22, 2026
10:00 EDT / 16:00 CEST / 14:00 UTC
The OWASP Top 10 has been the closest thing the industry has to a shared vocabulary for web application risk since 2003. It helped establish PCI DSS, gets referenced directly by national security bodies, and shows up in more RFPs than most teams would like. The 2025 edition, finalized on December 24, 2025, is the first refresh in four years, and the list moved.
Security Misconfiguration climbed four places. Software Supply Chain Failures arrived as its own category. Mishandling of Exceptional Conditions is brand new. Injection, which held the #1 spot for five straight editions, now sits at #5. Not because SQL injection got solved, but because the category absorbed XSS and the audit data moved on.
This session is not a reading of the list. Christian Wenz, who spends his working life conducting security audits and wrote the book on ASP.NET Core security, walks each item as it actually shows up in ASP.NET Core and Duende IdentityServer deployments: the C# that introduces the weakness, the configuration that closes it, and the ones your framework already handles so you can stop worrying about them.
Attendees leave knowing which items on the 2025 list genuinely apply to their stack, and with at least one change they can ship this sprint.
What You'll Learn
• How the list is actually built, and why that matters: CWE data submitted by practitioners running real audits, incidence rate rather than raw frequency, and a survey to catch the risks the backward-looking data can't see yet. Understanding the methodology tells you which items to weigh for your stack instead of treating all ten as equal.
• The four that matter most for ASP.NET Core and IdentityServer:
o Broken Access Control (#1): Mass assignment and the two-line fix. Why CSRF now lives inside this category rather than standing on its own. SSRF, and what it means when your own app is the helpful intermediary attaching access tokens to a forwarded request.
o Security Misconfiguration (#2): Up four places, partly because misconfiguration is the easiest thing in the world for an auditor to test. The security HTTP headers worth setting, and what already ships in every official Duende IdentityServer template.
o Injection (#5): Why SQL injection should be a solved problem in 2026, why the category still ranks anyway, and what CSP and the Trusted Types API actually buy you against XSS.
o Authentication Failures (#7): Password complexity theater versus length, what NIST and CISA actually recommend, and the one-line change in ASP.NET Core Identity.
• The new arrivals: Software Supply Chain Failures and Mishandling of Exceptional Conditions are two categories that weren't on the 2021 list in this form, and the patch-fast-versus-patch-safe tension that put the first one there.
• The process half of the list: Logging and alerting only count together, like a backup and a restore. What IdentityServer logs by default, what security event auditing adds, and how to get it into OpenTelemetry.
• Live C#, not slideware: Each risk shown with the code that creates it and the code that closes it.
Speakers
Christian Wenz | Security Consultant, Author & Duende Contributor
Christian Wenz is a consultant, software architect, and trainer specializing in web technologies and security. He has written or co-written over 100 books, including ASP.NET Core Security (Manning), and has been a Microsoft MVP for Developer Technologies since 2004. His day job is conducting security audits and helping teams harden real code bases — the same kind of work that feeds the data behind lists like the OWASP Top 10. Christian writes on web application security for the Duende blog and hosts Duende's web application security video series on YouTube.
