NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53461HighMagick.NET-Q16-AnyCPU: ImageMagick has out-of-bounds write in ICON decoder due to incorrect loopCVE-2026-53460HighMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass can Trigger an Out-of-Memory conditionCVE-2026-49219MediumMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass can read disallowed files via symlinkCVE-2026-49218HighMagick.NET-Q16-AnyCPU: ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensionsCVE-2026-48994MediumMagick.NET-Q16-AnyCPU: ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systemsCVE-2026-48734MediumMagick.NET-Q16-AnyCPU: ImageMagick Vulnerable to Stack Overflow in its MVG DecoderCVE-2026-48733MediumMagick.NET-Q16-AnyCPU: ImageMagick has an Infinite Loop in subimage-search with crafted imageCVE-2026-48724MediumMagick.NET-Q16-AnyCPU: ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering methodCVE-2026-48517MediumMessagePack: MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic argumentsCVE-2026-48516MediumMessagePack: MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settingsCVE-2026-48515MediumMessagePack: MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensionsCVE-2026-48514MediumMessagePack: MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte lengthCVE-2026-48513MediumMessagePack: MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcementCVE-2026-48512MediumMessagePack: MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcementCVE-2026-48511MediumMessagePack: MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted mapsCVE-2026-48510MediumMessagePack: MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengthsCVE-2026-48509MediumMessagePack: MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodiesCVE-2026-48506HighMessagePack: MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depthCVE-2026-48502HighMessagePack: MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflowsCVE-2026-54784HighCoreWCF.Primitives: CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentialityCVE-2026-54783HighCoreWCF.Primitives: CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messagesCVE-2026-54782CriticalCoreWCF.Primitives: CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validationCVE-2026-54781HighCoreWCF.Primitives: CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforcedCVE-2026-54780LowCoreWCF.Primitives: CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite BypassCVE-2026-54779MediumCoreWCF.Primitives: CoreWCF: SAML token replay protection is inoperative

Stop the waste.
Protect your environment with Kodem.