CVE Archive

NuGet Vulnerability Archive

Recent and critical CVEs affecting NuGet packages. Kodem’s runtime-powered SCA identifies which are actually reachable in your applications.

Top affected packages
Recent NuGet CVEs
CVE
Package / summary
Severity
CVE-2026-54784
CoreWCF.Primitives · CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
High
CVE-2026-54783
CoreWCF.Primitives · CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature…
High
CVE-2026-54782
CoreWCF.Primitives · CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature…
Critical
CVE-2026-54781
CoreWCF.Primitives · CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not…
High
CVE-2026-54779
CoreWCF.Primitives · CoreWCF: SAML token replay protection is inoperative
Medium
CVE-2026-54778
CoreWCF.UnixDomainSocket · CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
Medium
CVE-2026-54777
CoreWCF.NetNamedPipe · CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe…
Medium
CVE-2026-54776
CoreWCF.UnixDomainSocket · CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that…
Medium
CVE-2026-54775
CoreWCF.Kafka · CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value…
Medium
CVE-2026-54774
CoreWCF.Primitives · CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing…
High
CVE-2026-54773
CoreWCF.Primitives · CoreWCF: WS-Security signature substitution via document-wide Signature lookup
Medium
CVE-2026-54772
CoreWCF.NetFramingBase · CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp /…
High
CVE-2026-55254
NCalc.Core · NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
Medium
CVE-2026-45491
Microsoft.NETCore.App.Runtime.linux-x64 · Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability
Medium
CVE-2026-45591
Microsoft.AspNetCore.App.Runtime.linux-x64 · Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service…
High
CVE-2026-48109
MessagePack · MessagePack's LZ4 decompression may fail with AccessViolationException after…
High
CVE-2026-47761
tinymce · TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin…
High
CVE-2026-47762
tinymce · TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected`…
High
CVE-2026-47759
tinymce · TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce-…
High
CVE-2026-47760
tinymce · TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass…
High
CVE-2026-47166
Magick.NET-Q16-AnyCPU · ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
Medium
CVE-2026-47165
Magick.NET-Q16-AnyCPU · ImageMagick: Information Disclosure in distributed pixel cache server because…
Medium
CVE-2026-46693
Magick.NET-Q16-AnyCPU · ImageMagick: Race Condition in distributed pixel cache server can result in…
Medium
CVE-2026-46692
Magick.NET-Q16-AnyCPU · ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
Medium
CVE-2026-46609
Umbraco.Cms · Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
Medium
CVE-2026-46616
Umbraco.Cms · Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
Medium
CVE-2026-45785
OpenMcdf · OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on…
Medium
CVE-2026-46559
Magick.NET-Q16-AnyCPU · ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.
Medium
CVE-2026-46557
Magick.NET-Q16-AnyCPU · ImageMagick: Stack overflow in fx operation
Medium
CVE-2026-46523
Magick.NET-Q16-AnyCPU · ImageMagick: Use-After-Free in MSL decoder.
Medium
CVE-2026-46522
Magick.NET-Q16-AnyCPU · ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
High
CVE-2026-46521
Magick.NET-Q16-AnyCPU · ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
Medium
CVE-2026-46520
Magick.NET-Q16-AnyCPU · ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images…
High
CVE-2026-45664
Magick.NET-Q16-AnyCPU · ImageMagick: Policy Bypass in MNG coder could
Medium
CVE-2026-45624
Magick.NET-Q16-AnyCPU · ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
Medium
CVE-2026-35433
Microsoft.WindowsDesktop.App.Runtime.win-arm64 · Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege…
High
CVE-2026-42899
Microsoft.AspNetCore.App.Runtime.win-arm · Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service…
High
CVE-2026-32175
Microsoft.NetCore.App.Runtime.win-arm · Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability
High
CVE-2026-45031
Magick.NET-Q16-AnyCPU · ImageMagick: Policy Bypass in PSD decoder
Medium
CVE-2026-45358
Magick.NET-Q16-AnyCPU · ImageMagick: Out-of-Bounds Read of a single byte in meta encoder
Medium

Stop the waste.
Protect your environment with Kodem.