NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-50273HighDatadog.Trace: dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoSGHSA-Q3V2-XJ35-9GRXMediumUmbraco.AI: Umbraco.AI discloses sensitive application configuration valuesGHSA-7JVP-HJ45-2F2MHighScriban: Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter…CVE-2026-50268LowSteeltoe.Configuration.Encryption: Steeltoe: OAEP setting silently selects PKCS#1 v1.5 paddingCVE-2026-50267MediumSteeltoe.Configuration.Abstractions: Steeltoe: TLS private keys written to /tmp with default permissions, never deletedCVE-2026-50202MediumSteeltoe.Security.Authentication.JwtBearer: Steeltoe's static JWKS cache shared across schemes and never invalidatedCVE-2026-50201MediumSteeltoe.Management.Endpoint: Steeltoe's sensitive actuators (heapdump/env) only require Restricted permissionCVE-2026-50200HighSteeltoe.Management.Endpoint: Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwordsCVE-2026-50196HighSteeltoe.Discovery.Eureka: Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchCVE-2026-50194HighSteeltoe.Management.Endpoint: Steeltoe vulnerable to management-port isolation bypass via spoofed Host headerCVE-2026-48796MediumCefSharp.Common: CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folderCVE-2026-49451HighMicrosoft.OpenAPI: Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsingCVE-2026-53465MediumMagick.NET-Q16-AnyCPU: ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame imageCVE-2026-53464MediumMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in wand option parser when providing invalid argumentsGHSA-6Q7J-XR26-3H2CMediumScriban: Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 /…GHSA-Q6RR-FM2G-G5X8MediumScriban: Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of…CVE-2026-53463MediumMagick.NET-Q16-AnyCPU: ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect argumentsCVE-2026-53462MediumMagick.NET-Q16-AnyCPU: ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent failsCVE-2026-53461HighMagick.NET-Q16-AnyCPU: ImageMagick has out-of-bounds write in ICON decoder due to incorrect loopCVE-2026-53460HighMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass can Trigger an Out-of-Memory conditionCVE-2026-49219MediumMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass can read disallowed files via symlinkCVE-2026-49218HighMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensionsCVE-2026-48994MediumMagick.NET-Q16-AnyCPU: ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systemsCVE-2026-48734MediumMagick.NET-Q16-AnyCPU: ImageMagick Vulnerable to Stack Overflow in its MVG DecoderCVE-2026-48733MediumMagick.NET-Q16-AnyCPU: ImageMagick has an Infinite Loop in subimage-search with crafted image

Stop the waste.
Protect your environment with Kodem.