NuGet incidents
Recent NuGet vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
SSH.NET: before 2026.0.0
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
SIPSorcery: 10.0.5 → 10.0.14
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
SIPSorcery: before 10.0.14
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
Microsoft.NETCore.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Microsoft.NETCore.App.Runtime.linux-arm: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
Microsoft.NETCore.App.Runtime.linux-arm: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
Microsoft.NETCore.App.Runtime.win-arm64: 10.0.0 → 10.0.11
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
Magick.NET-Q16-AnyCPU: before 14.15.0
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.6
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
System.Security.Cryptography.Xml: 10.0.0 → 10.0.10
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10
NuGet Client Security Feature Bypass Vulnerability
NuGet Client Security Feature Bypass Vulnerability
NuGet.CommandLine: 4.6.0 → 5.11.6
Microsoft ASP.NET Core project templates vulnerable to denial of service
Microsoft ASP.NET Core project templates vulnerable to denial of service
System.IdentityModel.Tokens.Jwt: before 5.7.0
.NET Remote Code Execution vulnerability
.NET Remote Code Execution vulnerability
Microsoft.NetCore.App.Runtime.win-arm: 7.0.0 → 7.0.5
ASP.NET Core Information Disclosure Vulnerability
ASP.NET Core Information Disclosure Vulnerability
Microsoft.AspNetCore.Authentication.JwtBearer: 2.1.0 → 2.1.29
Tooling for NuGet
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.