Tagged “nuget”
CVEs tagged nuget, newest first.
151 CVEsRSS
CVE-2026-62871High· 7.8.NET Elevation of Privilege Vulnerability
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62898High· 7.5Microsoft QUIC Information Disclosure Vulnerability
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62899Medium· 5.9.NET Security Feature Bypass Vulnerability
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-53466Medium· 6.5ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
CVE-2026-32203High· 7.5Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
CVE-2026-59860HighMicrosoft Kiota: XML Doc-Comment Newline Breakout Code Injection
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
GHSA-76q6-2p6h-xjqrLow· 1.8ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title
ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title
CVE-2026-59861High· 7.5Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
CVE-2026-59862High· 7.5Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
CVE-2026-59859HighMicrosoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
CVE-2026-59864CriticalMicrosoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
CVE-2026-59867High· 7.1Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVE-2026-59863HighMicrosoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
CVE-2026-59865CriticalMicrosoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
CVE-2026-59866HighMicrosoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
GHSA-p5rm-jg5c-8c77MediumMicrosoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
CVE-2026-62343Medium· 4.7ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
CVE-2026-62363Medium· 5.0ImageMagick: Heap Buffer Over-Write in fx operation
ImageMagick: Heap Buffer Over-Write in fx operation
CVE-2026-62946Medium· 5.1ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
GHSA-qvxh-prvr-85w2Low· 3.7ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
GHSA-hwf3-r46v-5ggxLow· 2.9ImageMagick: Information Disclosure when printing profiles with debug enabled
ImageMagick: Information Disclosure when printing profiles with debug enabled
GHSA-6vxp-gfwf-hcr9Low· 2.9ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
GHSA-7c7m-fpjw-gwcqLow· 2.9ImageMagick: Memory Leak in color transformation to log colorspace when operation fails
ImageMagick: Memory Leak in color transformation to log colorspace when operation fails
GHSA-j8rh-v2r8-v94xLow· 2.9ImageMagick: Memory Leak in hough lines operation when an operation fails
ImageMagick: Memory Leak in hough lines operation when an operation fails
GHSA-99w9-hv66-rfv7Low· 2.9ImageMagick: Memory Leak in JNG encoder when a blob could not be opened
ImageMagick: Memory Leak in JNG encoder when a blob could not be opened
GHSA-jfq9-q63x-rc63Low· 2.9ImageMagick: Memory Leak in TIFF encoder when an allocation fails
ImageMagick: Memory Leak in TIFF encoder when an allocation fails
GHSA-h7f2-f9cc-h2gvLow· 3.7ImageMagick: Memory Leak in YUV decoder when opening of blob fails
ImageMagick: Memory Leak in YUV decoder when opening of blob fails
GHSA-r628-69v2-2f9cLow· 2.9ImageMagick: Memory Leak in MIFF encoder when allocaton fails
ImageMagick: Memory Leak in MIFF encoder when allocaton fails
GHSA-m596-67p7-69whLow· 2.9ImageMagick: Memory leak in VIFF encoder when allocation fails
ImageMagick: Memory leak in VIFF encoder when allocation fails
GHSA-h58x-r7f7-rh84Low· 3.7ImageMagick: Memory Leak in ICON decoder when allocation fails
ImageMagick: Memory Leak in ICON decoder when allocation fails