NuGet incidents
Recent NuGet vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
Microsoft.DiaSymReader.Native: 17.10.0-beta1.24272.1 → 18.9.0-beta1.26405.2
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Microsoft.AspNetCore.Server.IISIntegration: 11.0.0-preview.1 → 11.0.0-rc.1
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native: 17.10.0-beta1.24272.1 → 18.9.0-beta1.26405.2
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native: 17.10.0-beta1.24272.1 → 18.9.0-beta1.26405.2
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
Microsoft.Build.Tasks.Git: 10.0.102 → 10.0.111
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-x64: 10.0.0 → 10.0.10
Microsoft QUIC: Remote Code Execution Vulnerability
Microsoft QUIC: Remote Code Execution Vulnerability
Microsoft.Native.Quic.MsQuic.OpenSSL: 2.5.3 → 2.5.10
ImageMagick: Memory Leak when providing invalid options to the cli
ImageMagick: Memory Leak when providing invalid options to the cli
Magick.NET-Q16-AnyCPU: before 14.15.0
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
SSH.NET: before 2026.0.0
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
SIPSorcery: before 10.0.14
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
SIPSorcery: 10.0.5 → 10.0.14
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
Microsoft.NETCore.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Microsoft.NETCore.App.Runtime.linux-arm: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
Microsoft.NETCore.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
Microsoft.NETCore.App.Runtime.linux-arm: 10.0.0 → 10.0.11
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
Magick.NET-Q16-AnyCPU: before 14.15.0
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.6
ImageMagick: Heap Buffer Over-Write in fx operation
ImageMagick: Heap Buffer Over-Write in fx operation
Magick.NET-Q16-AnyCPU: before 14.15.0
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
Scriban: before 7.2.2
CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder
CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder
CefSharp.Common: before 148.0.90
Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx
Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx
Scriban: 3.0.0 → 7.2.1
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
Scriban: 6.6.0 → 7.2.1
Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability
Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability
Microsoft.NETCore.App.Runtime.linux-x64: 8.0.0 → 8.0.28
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
Microsoft.AspNetCore.App.Runtime.linux-x64: 8.0.0 → 8.0.28
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
MessagePack: before 2.5.301
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString
scriban: before 7.2.0
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
Magick.NET-Q16-AnyCPU: before 14.13.1
ImageMagick: Use-After-Free in MSL decoder.
ImageMagick: Use-After-Free in MSL decoder.
Magick.NET-Q16-AnyCPU: before 14.13.1
ImageMagick: Stack overflow in fx operation
ImageMagick: Stack overflow in fx operation
Magick.NET-Q16-AnyCPU: before 14.13.1
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
Microsoft.AspNetCore.App.Runtime.win-arm: 8.0.0 → 8.0.27
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
OpenTelemetry.Exporter.OpenTelemetryProtocol: 1.8.0 → 1.15.3
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
OpenTelemetry.Api: 0.5.0-beta.2 → 1.15.3
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
OpenTelemetry.Exporter.OpenTelemetryProtocol: 1.13.1 → 1.15.3
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
OpenTelemetry.Exporter.OpenTelemetryProtocol: 1.13.1 → 1.15.2
ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float
ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float
Magick.NET-Q16-AnyCPU: before 14.12.0
ImageMagick has an off-by-one error in MSL decoder could result in crash
ImageMagick has an off-by-one error in MSL decoder could result in crash
Magick.NET-Q16-AnyCPU: before 14.12.0
Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability
Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.6
Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.6
Defense in Depth update for NuGet Client
Defense in Depth update for NuGet Client
NuGet.Packaging: 4.9.0 → 4.9.7
ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.
ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.
Magick.NET-Q16-AnyCPU: before 14.12.0
Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.6
ImageMagick has an Out-of-bounds Write via InterpretImageFilename
ImageMagick has an Out-of-bounds Write via InterpretImageFilename
Magick.NET-Q16-AnyCPU: before 14.11.1
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
Magick.NET-Q16-AnyCPU: before 14.11.1
Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service
Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service
scriban: before 7.0.0
Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation
Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation
Scriban: before 7.0.0
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString
Scriban: before 7.0.0
Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException
Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException
Scriban: before 7.0.0
Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service
Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service
Scriban: before 7.0.0
Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse
Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse
scriban: before 7.0.0
Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix
Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix
Scriban: before 7.0.0
Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()
Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()
scriban: before 7.0.0
Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)
Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)
scriban: before 6.6.0
Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)
Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)
scriban: before 6.6.0
AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
AutoMapper: 16.0.0 → 16.1.1
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
Magick.NET-Q16-AnyCPU: before 14.10.4
ImageMagick has Heap Buffer Over-Read in BilateralBlurImage
ImageMagick has Heap Buffer Over-Read in BilateralBlurImage
Magick.NET-Q16-AnyCPU: before 14.10.4
ImageMagick has heap-based buffer overflow in UHDR encoder
ImageMagick has heap-based buffer overflow in UHDR encoder
Magick.NET-Q16-AnyCPU: before 14.10.4
.NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft.Bcl.Memory: 9.0.0 → 9.0.14
.NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft.AspNetCore.App.Runtime.linux-arm: 8.0.0 → 8.0.25
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
Azure.Mcp: 2.0.0-beta.1 → 2.0.0-beta.17
ImageMagick: Memory Leak in multiple coders that write raw pixel data
ImageMagick: Memory Leak in multiple coders that write raw pixel data
Magick.NET-Q16-AnyCPU: before 14.10.3
ImageMagick: Possible memory leak in ASHLAR encoder
ImageMagick: Possible memory leak in ASHLAR encoder
Magick.NET-Q16-AnyCPU: before 14.10.3
ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHDR images with large dimensions
ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHDR images with large dimensions
Magick.NET-Q16-AnyCPU: before 14.10.3
Image Magick has a Memory Leak in coders/ashlar.c
Image Magick has a Memory Leak in coders/ashlar.c
Magick.NET-Q16-AnyCPU: before 14.10.3
Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability
System.Security.Cryptography.Cose: 8.0.0 → 8.0.2
ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript
ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript
Magick.NET-Q8-x64: before 14.10.2
ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
Magick.NET-Q8-x64: before 14.10.2
ImageMagick releases an invalid pointer in BilateralBlur when memory allocation fails
ImageMagick releases an invalid pointer in BilateralBlur when memory allocation fails
Magick.NET-Q8-x64: before 14.10.2
ImageMagick's failure to limit the depth of SVG file reads caused a DoS attack
ImageMagick's failure to limit the depth of SVG file reads caused a DoS attack
Magick.NET-Q16-AnyCPU: before 14.10.1
ImageMagick's failure to limit MVG mutual causes Stack Overflow
ImageMagick's failure to limit MVG mutual causes Stack Overflow
Magick.NET-Q16-AnyCPU: before 14.10.1
Umbraco CMS has an arbitrary file upload vulnerability
Umbraco CMS has an arbitrary file upload vulnerability
Umbraco.Cms: all versions
ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)
ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)
Magick.NET-Q16-AnyCPU: before 14.10.0
ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
Magick.NET-Q16-x64: all versions
Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.10
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability
Microsoft.AspNetCore.Server.Kestrel.Core: before 2.3.6
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
KubernetesClient: before 17.0.14
imagemagick: heap-buffer overflow read in MNG magnification with alpha
imagemagick: heap-buffer overflow read in MNG magnification with alpha
Magick.NET-Q16-AnyCPU: before 14.8.0
ImageMagick has a Heap Buffer Overflow in InterpretImageFilename
ImageMagick has a Heap Buffer Overflow in InterpretImageFilename
Magick.NET-Q16-AnyCPU: before 14.7.0
ImageMagick has a heap-buffer-overflow
ImageMagick has a heap-buffer-overflow
Magick.NET-Q16-AnyCPU: before 13.2.0
ImageMagick has a Memory Leak in magick stream
ImageMagick has a Memory Leak in magick stream
Magick.NET-Q16-AnyCPU: before 14.7.0
ImageMagick has a Stack Buffer Overflow in image.c
ImageMagick has a Stack Buffer Overflow in image.c
Magick.NET-Q16-AnyCPU: before 14.7.0
ImageMagick has XMP profile write that triggers hang due to unbounded loop
ImageMagick has XMP profile write that triggers hang due to unbounded loop
Magick.NET-Q8-AnyCPU: before 14.7.0
Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates
Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates
CouchbaseNetClient: all versions
Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability
Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.6
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
Microsoft.Build.Tasks.Core: 15.8.166 → 15.9.30
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
YoutubeDLSharp: 1.0.0-beta4 → 1.1.2
OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API Package
OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API Package
OpenTelemetry.Api: 1.11.0 → 1.11.2
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.1
Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.1
Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.1
.NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
System.Formats.Nrbf: before 9.0.0
.NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
System.Formats.Nrbf: before 9.0.0
MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
MessagePack: before 2.5.187
tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users
tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users
Tgstation.Server.Api: 4.0.0 → 6.8.0
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
SixLabors.ImageSharp: before 2.1.9
CLSA Directory Traversal vulnerability
CLSA Directory Traversal vulnerability
Csla: before 5.5.4
SixLabors ImageSharp Out-of-bounds Write
SixLabors ImageSharp Out-of-bounds Write
SixLabors.ImageSharp: before 2.1.9
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Steeltoe.Discovery.Eureka: before 3.2.8
Microsoft Security Advisory CVE-2024-38095 | .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2024-38095 | .NET Denial of Service Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 8.0.0 → 8.0.7
Microsoft Security Advisory CVE-2024-30105 | .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2024-30105 | .NET Denial of Service Vulnerability
System.Text.Json: 7.0.0 → 8.0.4
NHibernate SQL injection vulnerability in discriminator mappings, static fields referenced in HQL, and some utilities
NHibernate SQL injection vulnerability in discriminator mappings, static fields referenced in HQL, and some utilities
NHibernate: before 5.4.9
Umbraco CMS Open Redirect Bypass Protection
Umbraco CMS Open Redirect Bypass Protection
UmbracoCms.Core: 8.18.5 → 8.18.14
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
UmbracoCms.Core: 8.0.0 → 8.18.13
Npgsql vulnerable to SQL Injection via Protocol Message Size Overflow
Npgsql vulnerable to SQL Injection via Protocol Message Size Overflow
Npgsql: 8.0.0 → 8.0.3
Blind SSRF Leads to Port Scan by using Webhooks
Blind SSRF Leads to Port Scan by using Webhooks
Umbraco.Cms.Core: 13.0.0 → 13.1.1
MSAL.NET applications targeting Xamarin Android and .NET Android (MAUI) susceptible to local denial of service
MSAL.NET applications targeting Xamarin Android and .NET Android (MAUI) susceptible to local denial of service
Microsoft.Identity.Client: 4.48.0 → 4.59.1
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
SixLabors.ImageSharp: before 2.1.8
SixLabors.ImageSharp vulnerable to data leakage
SixLabors.ImageSharp vulnerable to data leakage
SixLabors.ImageSharp: before 2.1.8
Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCore
Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCore
OpenTelemetry.Instrumentation.Http: before 1.8.1
WiX based installers are vulnerable to binary hijack when run as SYSTEM
WiX based installers are vulnerable to binary hijack when run as SYSTEM
wix: before 3.14.1
Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated files
Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated files
wix: before 3.14.1
Umbraco possible user enumeration
Umbraco possible user enumeration
UmbracoCMS: 10.0.0 → 10.8.5
CoreWCF NetFraming based services can leave connections open when they should be closed
CoreWCF NetFraming based services can leave connections open when they should be closed
CoreWCF.NetFramingBase: 1.4.0 → 1.4.2
Use After Free in SixLabors.ImageSharp
Use After Free in SixLabors.ImageSharp
SixLabors.ImageSharp: 3.0.0 → 3.1.3
NuGet Client Security Feature Bypass Vulnerability
NuGet Client Security Feature Bypass Vulnerability
NuGet.CommandLine: 4.6.0 → 5.11.6
WiX Toolset's .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges
WiX Toolset's .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges
wix: 4.0.0 → 4.0.4
TrueLayer.Client SSRF when fetching payment or payment provider
TrueLayer.Client SSRF when fetching payment or payment provider
TrueLayer.Client: before 1.6.0
Microsoft.IdentityModel.Protocols.SignedHttpRequest remote code execution vulnerability
Microsoft.IdentityModel.Protocols.SignedHttpRequest remote code execution vulnerability
Microsoft.IdentityModel.Protocols.SignedHttpRequest: before 6.34.0
Microsoft ASP.NET Core project templates vulnerable to denial of service
Microsoft ASP.NET Core project templates vulnerable to denial of service
System.IdentityModel.Tokens.Jwt: before 5.7.0
DOM-XSS on Backoffice login screen.
DOM-XSS on Backoffice login screen.
Umbraco.CMS: 10.0.0 → 10.8.1
Brute force exploit can be used to collect valid usernames
Brute force exploit can be used to collect valid usernames
Umbraco.CMS: 8.0.0 → 8.18.10
Stored XSS via SVG File Upload
Stored XSS via SVG File Upload
Umbraco.CMS: 7.0.0 → 7.15.11
Using the directory back payload (“/../”) in a package name allows placement of package in other folders.
Using the directory back payload (“/../”) in a package name allows placement of package in other folders.
Umbraco.CMS: 8.0.0 → 8.18.10
Backoffice User can bypass "Publish" restriction
Backoffice User can bypass "Publish" restriction
Umbraco.CMS: 8.0.0 → 8.18.10
HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content
HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content
HtmlSanitizer: before 8.0.723
Imageflow affected by libwebp zero-day and should not be used with malicious source images.
Imageflow affected by libwebp zero-day and should not be used with malicious source images.
Imageflow.AllPlatforms: before 0.10.2
NuGet Client Remote Code Execution Vulnerability
NuGet Client Remote Code Execution Vulnerability
NuGet.PackageManagement: 6.0.0 → 6.0.5
Snowflake Connector .Net Command Injection
Snowflake Connector .Net Command Injection
Snowflake.Data: before 2.0.18
.NET Remote Code Execution vulnerability
.NET Remote Code Execution vulnerability
Microsoft.NetCore.App.Runtime.win-arm: 7.0.0 → 7.0.5
Snappier vulnerable to buffer overrun due to improper restriction of operations within the bounds of a memory buffer
Snappier vulnerable to buffer overrun due to improper restriction of operations within the bounds of a memory buffer
Snappier: 1.1.0 → 1.1.1
CoreFTP Directory Traversal
CoreFTP Directory Traversal
CoreFtp: all versions
ASP.NET Core Information Disclosure Vulnerability
ASP.NET Core Information Disclosure Vulnerability
Microsoft.AspNetCore.Authentication.JwtBearer: 2.1.0 → 2.1.29
Directory Traversal in elFinder.AspNet
Directory Traversal in elFinder.AspNet
elFinder.AspNet: before 1.1.1
Unrestricted Upload of File with Dangerous Type in Umbraco CMS
Unrestricted Upload of File with Dangerous Type in Umbraco CMS
UmbracoCms: before 8.5.4
Authenticated path traversal in Umbraco CMS
Authenticated path traversal in Umbraco CMS
UmbracoCms: before 8.9.2
Incorrect permission enforcement in UmbracoCms
Incorrect permission enforcement in UmbracoCms
UmbracoCms: before 8.10.0
XSS in HtmlSanitizer
XSS in HtmlSanitizer
HtmlSanitizer: before 5.0.372
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
Sustainsys.Saml2: before 1.0.2
Internal NCryptDecrypt method could be used externally from WindowsHello library.
Internal NCryptDecrypt method could be used externally from WindowsHello library.
HaemmerElectronics.SeppPenner.WindowsHello: before 1.0.4
Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack
Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack
MessagePack: before 1.9.11
Directory Traversal in SharpCompress
Directory Traversal in SharpCompress
SharpCompress: before 0.21.0
DotNetZip Zip-Slip Vulnerability
DotNetZip Zip-Slip Vulnerability
DotNetZip: before 1.11.0
Tooling for NuGet
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.