NuGet incidents

Recent NuGet vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

CRITICALNuGet

Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

Microsoft.DiaSymReader.Native: 17.10.0-beta1.24272.1 → 18.9.0-beta1.26405.2

6 days ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability

Microsoft.AspNetCore.Server.IISIntegration: 11.0.0-preview.1 → 11.0.0-rc.1

6 days ago
CRITICALNuGet

Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

Microsoft.DiaSymReader.Native: 17.10.0-beta1.24272.1 → 18.9.0-beta1.26405.2

6 days ago
CRITICALNuGet

Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability

Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability

Microsoft.DiaSymReader.Native: 17.10.0-beta1.24272.1 → 18.9.0-beta1.26405.2

6 days ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability

Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability

Microsoft.Build.Tasks.Git: 10.0.102 → 10.0.111

1 week ago
CRITICALNuGet

Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability

Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability

Microsoft.WindowsDesktop.App.Runtime.win-x64: 10.0.0 → 10.0.10

1 week ago
CRITICALNuGet

Microsoft QUIC: Remote Code Execution Vulnerability

Microsoft QUIC: Remote Code Execution Vulnerability

Microsoft.Native.Quic.MsQuic.OpenSSL: 2.5.3 → 2.5.10

1 week ago
MEDIUMNuGet

ImageMagick: Memory Leak when providing invalid options to the cli

ImageMagick: Memory Leak when providing invalid options to the cli

Magick.NET-Q16-AnyCPU: before 14.15.0

1 week ago
HIGHNuGet

SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames

SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames

SSH.NET: before 2026.0.0

4 weeks ago
HIGHNuGet

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

SIPSorcery: before 10.0.14

4 weeks ago
HIGHNuGet

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)

SIPSorcery: 10.0.5 → 10.0.14

4 weeks ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability

Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability

Microsoft.NETCore.App.Runtime.win-arm64: 10.0.0 → 10.0.11

1 month ago
CRITICALNuGet

Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability

Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability

Microsoft.NETCore.App.Runtime.linux-arm: 10.0.0 → 10.0.11

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability

Microsoft.NETCore.App.Runtime.win-arm64: 10.0.0 → 10.0.11

1 month ago
CRITICALNuGet

Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability

Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability

Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11

1 month ago
CRITICALNuGet

Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability

Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability

Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11

1 month ago
CRITICALNuGet

Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability

Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability

Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability

Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability

Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11

1 month ago
CRITICALNuGet

Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability

Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability

Microsoft.WindowsDesktop.App.Runtime.win-arm64: 10.0.0 → 10.0.11

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability

Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability

Microsoft.NETCore.App.Runtime.linux-arm: 10.0.0 → 10.0.11

1 month ago
MEDIUMNuGet

ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow

ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow

Magick.NET-Q16-AnyCPU: before 14.15.0

1 month agoEPSS 0%
HIGHNuGet

Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability

System.Security.Cryptography.Xml: 10.0.0 → 10.0.6

1 month ago
HIGHNuGet

ImageMagick: Heap Buffer Over-Write in fx operation

ImageMagick: Heap Buffer Over-Write in fx operation

Magick.NET-Q16-AnyCPU: before 14.15.0

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability

System.Security.Cryptography.Xml: 10.0.0 → 10.0.10

1 month agoEPSS 1%
HIGHNuGet

Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability

Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability

System.Security.Cryptography.Xml: 10.0.0 → 10.0.10

1 month agoEPSS 1%
HIGHNuGet

Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability

System.Security.Cryptography.Xml: 10.0.0 → 10.0.10

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10

1 month ago
CRITICALNuGet

Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability

Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability

System.Security.Cryptography.Xml: 10.0.0 → 10.0.10

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability

System.Security.Cryptography.Xml: 10.0.0 → 10.0.10

1 month ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability

Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.10

1 month ago
HIGHNuGet

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

Scriban: before 7.2.2

2 months ago
HIGHNuGet

CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder

CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder

CefSharp.Common: before 148.0.90

2 months ago
MODERATENuGet

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

Scriban: 3.0.0 → 7.2.1

2 months ago
MODERATENuGet

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

Scriban: 6.6.0 → 7.2.1

2 months ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability

Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability

Microsoft.NETCore.App.Runtime.linux-x64: 8.0.0 → 8.0.28

3 months ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability

Microsoft.AspNetCore.App.Runtime.linux-x64: 8.0.0 → 8.0.28

3 months ago
HIGHNuGet

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

MessagePack: before 2.5.301

3 months ago
HIGHNuGet

Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString

Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString

scriban: before 7.2.0

3 months ago
HIGHNuGet

ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion

ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion

Magick.NET-Q16-AnyCPU: before 14.13.1

4 months ago
HIGHNuGet

ImageMagick: Use-After-Free in MSL decoder.

ImageMagick: Use-After-Free in MSL decoder.

Magick.NET-Q16-AnyCPU: before 14.13.1

4 months ago
HIGHNuGet

ImageMagick: Stack overflow in fx operation

ImageMagick: Stack overflow in fx operation

Magick.NET-Q16-AnyCPU: before 14.13.1

4 months ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability

Microsoft.AspNetCore.App.Runtime.win-arm: 8.0.0 → 8.0.27

4 months ago
HIGHNuGet

OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter

OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter

OpenTelemetry.Exporter.OpenTelemetryProtocol: 1.8.0 → 1.15.3

4 months ago
MEDIUMNuGet

OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers

OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers

OpenTelemetry.Api: 0.5.0-beta.2 → 1.15.3

4 months ago
HIGHNuGet

OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling

OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling

OpenTelemetry.Exporter.OpenTelemetryProtocol: 1.13.1 → 1.15.3

4 months ago
HIGHNuGet

OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies

OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies

OpenTelemetry.Exporter.OpenTelemetryProtocol: 1.13.1 → 1.15.2

4 months ago
HIGHNuGet

ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float

ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float

Magick.NET-Q16-AnyCPU: before 14.12.0

5 months ago
HIGHNuGet

ImageMagick has an off-by-one error in MSL decoder could result in crash

ImageMagick has an off-by-one error in MSL decoder could result in crash

Magick.NET-Q16-AnyCPU: before 14.12.0

5 months ago
LOWNuGet

Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability

Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 10.0.0 → 10.0.6

5 months ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

System.Security.Cryptography.Xml: 10.0.0 → 10.0.6

5 months ago
LOWNuGet

Defense in Depth update for NuGet Client

Defense in Depth update for NuGet Client

NuGet.Packaging: 4.9.0 → 4.9.7

5 months ago
HIGHNuGet

ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.

ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.

Magick.NET-Q16-AnyCPU: before 14.12.0

5 months ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability

System.Security.Cryptography.Xml: 10.0.0 → 10.0.6

5 months ago
HIGHNuGet

ImageMagick has an Out-of-bounds Write via InterpretImageFilename

ImageMagick has an Out-of-bounds Write via InterpretImageFilename

Magick.NET-Q16-AnyCPU: before 14.11.1

5 months ago
MEDIUMNuGet

ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction

ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction

Magick.NET-Q16-AnyCPU: before 14.11.1

5 months ago
HIGHNuGet

Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service

Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service

scriban: before 7.0.0

5 months ago
HIGHNuGet

Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation

Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation

Scriban: before 7.0.0

5 months ago
HIGHNuGet

Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString

Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString

Scriban: before 7.0.0

5 months ago
HIGHNuGet

Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException

Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException

Scriban: before 7.0.0

5 months ago
HIGHNuGet

Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service

Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service

Scriban: before 7.0.0

5 months ago
HIGHNuGet

Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse

Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse

scriban: before 7.0.0

5 months ago
HIGHNuGet

Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix

Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix

Scriban: before 7.0.0

5 months ago
HIGHNuGet

Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()

Scriban has an authorization bypass due to stale include cache surviving TemplateContext.Reset()

scriban: before 7.0.0

5 months ago
HIGHNuGet

Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)

Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)

scriban: before 6.6.0

6 months ago
HIGHNuGet

Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)

Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)

scriban: before 6.6.0

6 months ago
HIGHNuGet

AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion

AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion

AutoMapper: 16.0.0 → 16.1.1

6 months ago
HIGHNuGet

ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder

ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder

Magick.NET-Q16-AnyCPU: before 14.10.4

6 months ago
MEDIUMNuGet

ImageMagick has Heap Buffer Over-Read in BilateralBlurImage

ImageMagick has Heap Buffer Over-Read in BilateralBlurImage

Magick.NET-Q16-AnyCPU: before 14.10.4

6 months ago
HIGHNuGet

ImageMagick has heap-based buffer overflow in UHDR encoder

ImageMagick has heap-based buffer overflow in UHDR encoder

Magick.NET-Q16-AnyCPU: before 14.10.4

6 months ago
HIGHNuGet

.NET Denial of Service Vulnerability

.NET Denial of Service Vulnerability

Microsoft.Bcl.Memory: 9.0.0 → 9.0.14

6 months ago
HIGHNuGet

.NET Denial of Service Vulnerability

.NET Denial of Service Vulnerability

Microsoft.AspNetCore.App.Runtime.linux-arm: 8.0.0 → 8.0.25

6 months ago
CRITICALNuGet

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Azure.Mcp: 2.0.0-beta.1 → 2.0.0-beta.17

6 months ago
MEDIUMNuGet

ImageMagick: Memory Leak in multiple coders that write raw pixel data

ImageMagick: Memory Leak in multiple coders that write raw pixel data

Magick.NET-Q16-AnyCPU: before 14.10.3

6 months ago
MEDIUMNuGet

ImageMagick: Possible memory leak in ASHLAR encoder

ImageMagick: Possible memory leak in ASHLAR encoder

Magick.NET-Q16-AnyCPU: before 14.10.3

6 months ago
HIGHNuGet

ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHDR images with large dimensions

ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHDR images with large dimensions

Magick.NET-Q16-AnyCPU: before 14.10.3

6 months ago
MEDIUMNuGet

Image Magick has a Memory Leak in coders/ashlar.c

Image Magick has a Memory Leak in coders/ashlar.c

Magick.NET-Q16-AnyCPU: before 14.10.3

6 months ago
HIGHNuGet

Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability

Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability

System.Security.Cryptography.Cose: 8.0.0 → 8.0.2

7 months ago
HIGHNuGet

ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript

ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript

Magick.NET-Q8-x64: before 14.10.2

7 months ago
HIGHNuGet

ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load

ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load

Magick.NET-Q8-x64: before 14.10.2

7 months ago
HIGHNuGet

ImageMagick releases an invalid pointer in BilateralBlur when memory allocation fails

ImageMagick releases an invalid pointer in BilateralBlur when memory allocation fails

Magick.NET-Q8-x64: before 14.10.2

7 months ago
MEDIUMNuGet

ImageMagick's failure to limit the depth of SVG file reads caused a DoS attack

ImageMagick's failure to limit the depth of SVG file reads caused a DoS attack

Magick.NET-Q16-AnyCPU: before 14.10.1

8 months ago
MEDIUMNuGet

ImageMagick's failure to limit MVG mutual causes Stack Overflow

ImageMagick's failure to limit MVG mutual causes Stack Overflow

Magick.NET-Q16-AnyCPU: before 14.10.1

8 months ago
CRITICALNuGet

Umbraco CMS has an arbitrary file upload vulnerability

Umbraco CMS has an arbitrary file upload vulnerability

Umbraco.Cms: all versions

8 months ago
HIGHNuGet

ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)

ImageMagick is vulnerable to an integer Overflow in TIM decoder leading to out of bounds read (32-bit only)

Magick.NET-Q16-AnyCPU: before 14.10.0

9 months ago
HIGHNuGet

ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)

ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)

Magick.NET-Q16-x64: all versions

10 months ago
HIGHNuGet

Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability

Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.10

11 months ago
HIGHNuGet

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability

Microsoft.AspNetCore.Server.Kestrel.Core: before 2.3.6

11 months ago
HIGHNuGet

Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain

Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain

KubernetesClient: before 17.0.14

0 years ago
HIGHNuGet

imagemagick: heap-buffer overflow read in MNG magnification with alpha

imagemagick: heap-buffer overflow read in MNG magnification with alpha

Magick.NET-Q16-AnyCPU: before 14.8.0

1 year ago
MEDIUMNuGet

ImageMagick has a Heap Buffer Overflow in InterpretImageFilename

ImageMagick has a Heap Buffer Overflow in InterpretImageFilename

Magick.NET-Q16-AnyCPU: before 14.7.0

1 year ago
MEDIUMNuGet

ImageMagick has a heap-buffer-overflow

ImageMagick has a heap-buffer-overflow

Magick.NET-Q16-AnyCPU: before 13.2.0

1 year ago
MEDIUMNuGet

ImageMagick has a Memory Leak in magick stream

ImageMagick has a Memory Leak in magick stream

Magick.NET-Q16-AnyCPU: before 14.7.0

1 year ago
HIGHNuGet

ImageMagick has a Stack Buffer Overflow in image.c

ImageMagick has a Stack Buffer Overflow in image.c

Magick.NET-Q16-AnyCPU: before 14.7.0

1 year ago
HIGHNuGet

ImageMagick has XMP profile write that triggers hang due to unbounded loop

ImageMagick has XMP profile write that triggers hang due to unbounded loop

Magick.NET-Q8-AnyCPU: before 14.7.0

1 year ago
HIGHNuGet

Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates

Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates

CouchbaseNetClient: all versions

1 year ago
CRITICALNuGet

Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability

Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.6

1 year ago
CRITICALNuGet

Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability

Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability

Microsoft.Build.Tasks.Core: 15.8.166 → 15.9.30

1 year ago
HIGHNuGet

YoutubeDLSharp allows command injection on windows system due to non sanitized arguments

YoutubeDLSharp allows command injection on windows system due to non sanitized arguments

YoutubeDLSharp: 1.0.0-beta4 → 1.1.2

1 year ago
HIGHNuGet

OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API Package

OpenTelemetry .NET has Denial of Service (DoS) Vulnerability in API Package

OpenTelemetry.Api: 1.11.0 → 1.11.2

1 year ago
CRITICALNuGet

Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability

Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.1

1 year ago
CRITICALNuGet

Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability

Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.1

1 year ago
CRITICALNuGet

Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability

Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 9.0.0 → 9.0.1

1 year ago
CRITICALNuGet

.NET Remote Code Execution Vulnerability

.NET Remote Code Execution Vulnerability

System.Formats.Nrbf: before 9.0.0

1 year ago
HIGHNuGet

.NET Denial of Service Vulnerability

.NET Denial of Service Vulnerability

System.Formats.Nrbf: before 9.0.0

1 year ago
MODERATENuGet

MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow

MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow

MessagePack: before 2.5.187

1 year ago
HIGHNuGet

tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users

tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users

Tgstation.Server.Api: 4.0.0 → 6.8.0

2 years ago
MEDIUMNuGet

SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder

SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder

SixLabors.ImageSharp: before 2.1.9

2 years ago
CRITICALNuGet

CLSA Directory Traversal vulnerability

CLSA Directory Traversal vulnerability

Csla: before 5.5.4

2 years ago
HIGHNuGet

SixLabors ImageSharp Out-of-bounds Write

SixLabors ImageSharp Out-of-bounds Write

SixLabors.ImageSharp: before 2.1.9

2 years ago
MEDIUMNuGet

Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error

Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error

Steeltoe.Discovery.Eureka: before 3.2.8

2 years ago
HIGHNuGet

Microsoft Security Advisory CVE-2024-38095 | .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2024-38095 | .NET Denial of Service Vulnerability

Microsoft.NetCore.App.Runtime.linux-arm: 8.0.0 → 8.0.7

2 years ago
HIGHNuGet

Microsoft Security Advisory CVE-2024-30105 | .NET Denial of Service Vulnerability

Microsoft Security Advisory CVE-2024-30105 | .NET Denial of Service Vulnerability

System.Text.Json: 7.0.0 → 8.0.4

2 years ago
HIGHNuGet

NHibernate SQL injection vulnerability in discriminator mappings, static fields referenced in HQL, and some utilities

NHibernate SQL injection vulnerability in discriminator mappings, static fields referenced in HQL, and some utilities

NHibernate: before 5.4.9

2 years ago
MEDIUMNuGet

Umbraco CMS Open Redirect Bypass Protection

Umbraco CMS Open Redirect Bypass Protection

UmbracoCms.Core: 8.18.5 → 8.18.14

2 years ago
HIGHNuGet

Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane

Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane

UmbracoCms.Core: 8.0.0 → 8.18.13

2 years ago
CRITICALNuGet

Npgsql vulnerable to SQL Injection via Protocol Message Size Overflow

Npgsql vulnerable to SQL Injection via Protocol Message Size Overflow

Npgsql: 8.0.0 → 8.0.3

2 years ago
MEDIUMNuGet

Blind SSRF Leads to Port Scan by using Webhooks

Blind SSRF Leads to Port Scan by using Webhooks

Umbraco.Cms.Core: 13.0.0 → 13.1.1

2 years ago
MEDIUMNuGet

MSAL.NET applications targeting Xamarin Android and .NET Android (MAUI) susceptible to local denial of service

MSAL.NET applications targeting Xamarin Android and .NET Android (MAUI) susceptible to local denial of service

Microsoft.Identity.Client: 4.48.0 → 4.59.1

2 years ago
MEDIUMNuGet

SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value

SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value

SixLabors.ImageSharp: before 2.1.8

2 years ago
HIGHNuGet

SixLabors.ImageSharp vulnerable to data leakage

SixLabors.ImageSharp vulnerable to data leakage

SixLabors.ImageSharp: before 2.1.8

2 years ago
MEDIUMNuGet

Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCore

Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCore

OpenTelemetry.Instrumentation.Http: before 1.8.1

2 years ago
CRITICALNuGet

WiX based installers are vulnerable to binary hijack when run as SYSTEM

WiX based installers are vulnerable to binary hijack when run as SYSTEM

wix: before 3.14.1

2 years ago
HIGHNuGet

Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated files

Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated files

wix: before 3.14.1

2 years ago
MEDIUMNuGet

Umbraco possible user enumeration

Umbraco possible user enumeration

UmbracoCMS: 10.0.0 → 10.8.5

2 years ago
HIGHNuGet

CoreWCF NetFraming based services can leave connections open when they should be closed

CoreWCF NetFraming based services can leave connections open when they should be closed

CoreWCF.NetFramingBase: 1.4.0 → 1.4.2

2 years ago
HIGHNuGet

Use After Free in SixLabors.ImageSharp

Use After Free in SixLabors.ImageSharp

SixLabors.ImageSharp: 3.0.0 → 3.1.3

2 years ago
HIGHNuGet

NuGet Client Security Feature Bypass Vulnerability

NuGet Client Security Feature Bypass Vulnerability

NuGet.CommandLine: 4.6.0 → 5.11.6

2 years ago
CRITICALNuGet

WiX Toolset's .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges

WiX Toolset's .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges

wix: 4.0.0 → 4.0.4

2 years ago
HIGHNuGet

TrueLayer.Client SSRF when fetching payment or payment provider

TrueLayer.Client SSRF when fetching payment or payment provider

TrueLayer.Client: before 1.6.0

2 years ago
HIGHNuGet

Microsoft.IdentityModel.Protocols.SignedHttpRequest remote code execution vulnerability

Microsoft.IdentityModel.Protocols.SignedHttpRequest remote code execution vulnerability

Microsoft.IdentityModel.Protocols.SignedHttpRequest: before 6.34.0

2 years ago
HIGHNuGet

Microsoft ASP.NET Core project templates vulnerable to denial of service

Microsoft ASP.NET Core project templates vulnerable to denial of service

System.IdentityModel.Tokens.Jwt: before 5.7.0

2 years ago
MEDIUMNuGet

DOM-XSS on Backoffice login screen.

DOM-XSS on Backoffice login screen.

Umbraco.CMS: 10.0.0 → 10.8.1

2 years ago
LOWNuGet

Brute force exploit can be used to collect valid usernames

Brute force exploit can be used to collect valid usernames

Umbraco.CMS: 8.0.0 → 8.18.10

2 years ago
LOWNuGet

Stored XSS via SVG File Upload

Stored XSS via SVG File Upload

Umbraco.CMS: 7.0.0 → 7.15.11

2 years ago
LOWNuGet

Using the directory back payload (“/../”) in a package name allows placement of package in other folders.

Using the directory back payload (“/../”) in a package name allows placement of package in other folders.

Umbraco.CMS: 8.0.0 → 8.18.10

2 years ago
LOWNuGet

Backoffice User can bypass "Publish" restriction

Backoffice User can bypass "Publish" restriction

Umbraco.CMS: 8.0.0 → 8.18.10

2 years ago
MEDIUMNuGet

HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content

HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content

HtmlSanitizer: before 8.0.723

2 years ago
CRITICALNuGet

Imageflow affected by libwebp zero-day and should not be used with malicious source images.

Imageflow affected by libwebp zero-day and should not be used with malicious source images.

Imageflow.AllPlatforms: before 0.10.2

2 years ago
CRITICALNuGet

NuGet Client Remote Code Execution Vulnerability

NuGet Client Remote Code Execution Vulnerability

NuGet.PackageManagement: 6.0.0 → 6.0.5

3 years ago
HIGHNuGet

Snowflake Connector .Net Command Injection

Snowflake Connector .Net Command Injection

Snowflake.Data: before 2.0.18

3 years ago
CRITICALNuGet

.NET Remote Code Execution vulnerability

.NET Remote Code Execution vulnerability

Microsoft.NetCore.App.Runtime.win-arm: 7.0.0 → 7.0.5

3 years ago
HIGHNuGet

Snappier vulnerable to buffer overrun due to improper restriction of operations within the bounds of a memory buffer

Snappier vulnerable to buffer overrun due to improper restriction of operations within the bounds of a memory buffer

Snappier: 1.1.0 → 1.1.1

3 years ago
MEDIUMNuGet

CoreFTP Directory Traversal

CoreFTP Directory Traversal

CoreFtp: all versions

4 years ago
HIGHNuGet

ASP.NET Core Information Disclosure Vulnerability

ASP.NET Core Information Disclosure Vulnerability

Microsoft.AspNetCore.Authentication.JwtBearer: 2.1.0 → 2.1.29

5 years ago
HIGHNuGet

Directory Traversal in elFinder.AspNet

Directory Traversal in elFinder.AspNet

elFinder.AspNet: before 1.1.1

5 years ago
HIGHNuGet

Unrestricted Upload of File with Dangerous Type in Umbraco CMS

Unrestricted Upload of File with Dangerous Type in Umbraco CMS

UmbracoCms: before 8.5.4

5 years ago
HIGHNuGet

Authenticated path traversal in Umbraco CMS

Authenticated path traversal in Umbraco CMS

UmbracoCms: before 8.9.2

5 years ago
MEDIUMNuGet

Incorrect permission enforcement in UmbracoCms

Incorrect permission enforcement in UmbracoCms

UmbracoCms: before 8.10.0

5 years ago
HIGHNuGet

XSS in HtmlSanitizer

XSS in HtmlSanitizer

HtmlSanitizer: before 5.0.372

5 years ago
HIGHNuGet

Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET

Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET

Sustainsys.Saml2: before 1.0.2

6 years ago
HIGHNuGet

Internal NCryptDecrypt method could be used externally from WindowsHello library.

Internal NCryptDecrypt method could be used externally from WindowsHello library.

HaemmerElectronics.SeppPenner.WindowsHello: before 1.0.4

6 years ago
HIGHNuGet

Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack

Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack

MessagePack: before 1.9.11

6 years ago
HIGHNuGet

Directory Traversal in SharpCompress

Directory Traversal in SharpCompress

SharpCompress: before 0.21.0

7 years ago
HIGHNuGet

DotNetZip Zip-Slip Vulnerability

DotNetZip Zip-Slip Vulnerability

DotNetZip: before 1.11.0

7 years ago

Tooling for NuGet

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionsGohexMavenPackagistPubPyPIRubyGemsSwiftURLcrates.ionpm