NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-50648HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service VulnerabilityCVE-2026-50524HighMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service VulnerabilityCVE-2026-47304HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass VulnerabilityCVE-2026-47302HighSystem.Security.Cryptography.Xml: Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service VulnerabilityCVE-2026-57108HighMicrosoft.NetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service VulnerabilityCVE-2026-54570MediumAngleSharp: AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point BypassCVE-2026-53598Highprompty: Prompty: Arbitrary file read via file reference expansionCVE-2026-50273HighDatadog.Trace: dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoSGHSA-Q3V2-XJ35-9GRXMediumUmbraco.AI: Umbraco.AI discloses sensitive application configuration valuesGHSA-7JVP-HJ45-2F2MHighScriban: Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter…CVE-2026-50268LowSteeltoe.Configuration.Encryption: Steeltoe: OAEP setting silently selects PKCS#1 v1.5 paddingCVE-2026-50267MediumSteeltoe.Configuration.Abstractions: Steeltoe: TLS private keys written to /tmp with default permissions, never deletedCVE-2026-50202MediumSteeltoe.Security.Authentication.JwtBearer: Steeltoe's static JWKS cache shared across schemes and never invalidatedCVE-2026-50201MediumSteeltoe.Management.Endpoint: Steeltoe's sensitive actuators (heapdump/env) only require Restricted permissionCVE-2026-50200HighSteeltoe.Management.Endpoint: Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwordsCVE-2026-50196HighSteeltoe.Discovery.Eureka: Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchCVE-2026-50194HighSteeltoe.Management.Endpoint: Steeltoe vulnerable to management-port isolation bypass via spoofed Host headerCVE-2026-48796MediumCefSharp.Common: CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folderCVE-2026-49451HighMicrosoft.OpenAPI: Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsingCVE-2026-53465MediumMagick.NET-Q16-AnyCPU: ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame imageCVE-2026-53464MediumMagick.NET-Q16-AnyCPU: ImageMagick: Memory Leak in wand option parser when providing invalid argumentsGHSA-6Q7J-XR26-3H2CMediumScriban: Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 /…GHSA-Q6RR-FM2G-G5X8MediumScriban: Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of…CVE-2026-53463MediumMagick.NET-Q16-AnyCPU: ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect argumentsCVE-2026-53462MediumMagick.NET-Q16-AnyCPU: ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails

Stop the waste.
Protect your environment with Kodem.