VulnSea

Tagged “nuget”

CVEs tagged nuget, newest first.

159 CVEsRSS

CVE-2026-57108High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-47302High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
GHSA-q3v2-xj35-9grxMedium· 4.9
2mo ago

Umbraco.AI discloses sensitive application configuration values

Umbraco.AI discloses sensitive application configuration values

▾ SunlitUmbraco · Umbraco.AIvia GHSA
GHSA-7jvp-hj45-2f2mHigh
2mo ago

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

▾ TwilightScriban · Scribanvia GHSA
CVE-2026-50194High· 8.2
2mo ago

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.41%via GHSA
CVE-2026-50196High· 7.5
2mo ago

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

▾ TwilightSteeltoe · Steeltoe.Discovery.EurekaEPSS 0.61%via GHSA
CVE-2026-50200High· 7.5
2mo ago

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.31%via GHSA
CVE-2026-50201Medium· 6.5
2mo ago

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

▾ SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.40%via GHSA
CVE-2026-50202Medium· 5.9
2mo ago

Steeltoe's static JWKS cache shared across schemes and never invalidated

Steeltoe's static JWKS cache shared across schemes and never invalidated

▾ SunlitSteeltoe · Steeltoe.Security.Authentication.JwtBearerEPSS 0.47%via GHSA
CVE-2026-50267Medium· 4.7
2mo ago

Steeltoe: TLS private keys written to /tmp with default permissions, never deleted

Steeltoe: TLS private keys written to /tmp with default permissions, never deleted

▾ SunlitSteeltoe · Steeltoe.Configuration.AbstractionsEPSS 0.08%via GHSA
CVE-2026-50268Low· 1.9
2mo ago

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

▾ SunlitSteeltoe · Steeltoe.Configuration.EncryptionEPSS 0.06%via GHSA
CVE-2026-49451High· 7.5
2mo ago

Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing

Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing

▾ TwilightMicrosoft · Microsoft.OpenAPIEPSS 1.2%via GHSA
CVE-2026-53463Medium· 4.3
3mo ago

ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments

ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.32%via GHSA
GHSA-q6rr-fm2g-g5x8Medium
3mo ago

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

▾ SunlitScriban · Scribanvia GHSA
GHSA-6q7j-xr26-3h2cMedium
3mo ago

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

▾ SunlitScriban · Scribanvia GHSA
CVE-2026-53464Medium· 4.0
3mo ago

ImageMagick: Memory Leak in wand option parser when providing invalid arguments

ImageMagick: Memory Leak in wand option parser when providing invalid arguments

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2026-53465Medium· 6.2
3mo ago

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.16%via GHSA
CVE-2026-53462Medium· 5.9
3mo ago

ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails

ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.37%via GHSA
CVE-2026-48502High
3mo ago

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

▾ TwilightMessagePack · MessagePackEPSS 0.44%via GHSA
CVE-2026-48506High· 7.5
3mo ago

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

▾ TwilightMessagePack · MessagePackEPSS 0.47%via GHSA
CVE-2026-48509Medium
3mo ago

MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies

MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies

▾ SunlitMessagePack · MessagePackEPSS 0.42%via GHSA
CVE-2026-48510Medium· 7.5
3mo ago

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48511Medium· 7.5
3mo ago

MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps

MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48512Medium
3mo ago

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48513Medium
3mo ago

MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement

MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48514Medium
3mo ago

MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length

MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48515Medium
3mo ago

MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions

MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48516Medium
3mo ago

MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings

MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48517Medium
3mo ago

MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments

MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments

▾ SunlitMessagePack · MessagePackEPSS 0.35%via GHSA
CVE-2026-48724Medium· 5.5
3mo ago

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVEs tagged “nuget” — page 4 · VulnSea