NuGet vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45288CriticalMarten: Marten has an injection vulnerability in its full-text search regConfig parameterGHSA-88Q9-CMP2-C2VQMediumoxidize-pdf: oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)CVE-2026-44788MediumSharpCompress: SharpCompress has directory traversal via directory entries in WriteToDirectory (zip slip variant)CVE-2026-44213MediumOpenTelemetry.Exporter.Instana: OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configuredCVE-2026-44503Highcom.microsoft.kiota:microsoft-kiota-abstractions: Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirectCVE-2026-44375HighNerdbank.MessagePack: Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowExceptionCVE-2026-44302HighSnappier: Snappier has an infinite loop during SnappyStream decompression with malformed framed inputCVE-2026-42348MediumOpenTelemetry.OpAmp.Client: OpAMP client reads unbounded HTTP response bodiesCVE-2026-43939HighYAFNET.Core: YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread ViewersCVE-2026-43937HighYAFNET.Core: YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`CVE-2026-43938HighYAFNET.Core: YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` HeaderCVE-2026-42191MediumOpenTelemetry.Exporter.OpenTelemetryProtocol: OpenTelemetry's disk retry default temp path enables local blob injection via OTLP ExporterCVE-2026-41484MediumOpenTelemetry.Exporter.OneCollector: OneCollector exporter reads unbounded HTTP response bodiesCVE-2026-41483MediumOpenTelemetry.Resources.Azure: OpenTelemetry.Resources.Azure has an unbounded HTTP response body readCVE-2026-41310MediumOpenTelemetry.Exporter.Zipkin: OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressureCVE-2026-42241MediumParquetSharp: ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type WidthCVE-2026-41173MediumOpenTelemetry.Sampler.AWS: OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body readsCVE-2026-40894MediumOpenTelemetry.Api: OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headersCVE-2026-40891MediumOpenTelemetry.Exporter.OpenTelemetryProtocol: OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handlingCVE-2026-40182MediumOpenTelemetry.Exporter.OpenTelemetryProtocol: OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodiesCVE-2026-40372CriticalMicrosoft.AspNetCore.DataProtection: Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of PrivilegeCVE-2026-41511MediumOpenMcdf: OpenMcdf has an Infinite loop DoS via crafted CFB directory cycleCVE-2026-41319MediumMailKit: MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgradeCVE-2026-41078MediumOpenTelemetry.Exporter.Jaeger: OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion pathGHSA-H39G-6X3C-7FQ9LowZio: Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment

Stop the waste.
Protect your environment with Kodem.