NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54780LowCoreWCF.Primitives: CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite BypassCVE-2026-54779MediumCoreWCF.Primitives: CoreWCF: SAML token replay protection is inoperativeCVE-2026-54778MediumCoreWCF.UnixDomainSocket: CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity ResolutionCVE-2026-54777MediumCoreWCF.NetNamedPipe: CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instanceCVE-2026-54776MediumCoreWCF.UnixDomainSocket: CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgradeCVE-2026-54775MediumCoreWCF.Kafka: CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.CVE-2026-54774HighCoreWCF.Primitives: CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificateCVE-2026-54773MediumCoreWCF.Primitives: CoreWCF: WS-Security signature substitution via document-wide Signature lookupCVE-2026-54772HighCoreWCF.NetFramingBase: CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshakeGHSA-2RM3-333W-XVC4MediumDotVVM: DotVVM: Unrestricted file uploadGHSA-C8QJ-JX8J-FG2WCriticalDotVVM: DotVVM: Missing authorization in AuthorizeActionFilterGHSA-C2G3-C4GC-W5WGHighDotVVM: ReDoS in DotVVM routingCVE-2026-55254MediumNCalc.Core: NCalc: Denial of Service via Unbounded and Non-Terminating Factorial EvaluationCVE-2026-45491MediumMicrosoft.NETCore.App.Runtime.linux-x64: Microsoft Security Advisory CVE-2026-45491 – .NET Tampering VulnerabilityCVE-2026-45591HighMicrosoft.AspNetCore.App.Runtime.linux-x64: Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service VulnerabilityCVE-2026-48109HighMessagePack: MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad inputCVE-2026-47761Hightinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injectionCVE-2026-47762Hightinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` commentsCVE-2026-47759Hightinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributesCVE-2026-47760Hightinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGsGHSA-92VJ-HP7M-GWCJMediumNerdbank.MessagePack: Nerdbank.MessagePack has Inefficient CPU ComputationGHSA-QJVR-435C-5FJHMediumNerdbank.MessagePack: Nerdbank.MessagePack has a memory amplification DoS in collection deserializationCVE-2026-47166MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Read in distributed pixel cache server CVE-2026-47165MediumMagick.NET-Q16-AnyCPU: ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication modelCVE-2026-46693MediumMagick.NET-Q16-AnyCPU: ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking

Stop the waste.
Protect your environment with Kodem.