Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-5mq7-rwhj-4fh9
  • NuGet/Steeltoe.Security.Authorization.Certificate
Steeltoe: Header-forwarded client cert lacks proof of private-key possession 4 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-67c9-f6v2-qv86
  • NuGet/Steeltoe.Discovery.Consul
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS) 4 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-hr73-3gpv-hh6q
  • NuGet/Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS) 4 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-8phw-xrj9-cpqp
  • NuGet/Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets 4 days ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-mggc-4xg6-vcxf
  • NuGet/SSH.NET
SSH.NET: ScpClient allows server-side RCE via default SCP path handling 4 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-wr57-hqmp-fgvh
  • NuGet/Umbraco.Cms
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion 4 days ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-rfx3-98h7-v3xp
  • NuGet/Marten
Marten's LINQ provider has SQL injection via unescaped string literals 4 days ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-v8pv-4842-x354
  • NuGet/OpenTelemetry.Resources.Host
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS 5 days ago
  • Fix available
  • Severity - 7.0 (High)
GHSA-8cp2-47hg-mfgh
  • NuGet/Microsoft.AspNetCore.Server.IISIntegration
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability 09 Sep
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-2j8r-3c22-8565
  • NuGet/Microsoft.DiaSymReader.Native
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability 09 Sep
  • Fix available
  • Severity - 8.8 (High)
GHSA-527h-q9f6-p7qx
  • NuGet/Microsoft.DiaSymReader.Native
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability 09 Sep
  • Fix available
  • Severity - 8.8 (High)
GHSA-63gh-g2x5-x69v
  • NuGet/Microsoft.DiaSymReader.Native
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability 09 Sep
  • Fix available
  • Severity - 8.8 (High)
GHSA-gh2h-rhph-h37g
  • NuGet/Microsoft.WindowsDesktop.App.Runtime.win-arm64
  • NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x64
  • NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x86
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability 08 Sep
  • Fix available
  • Severity - 7.8 (High)
GHSA-92f5-vc22-8j33
  • NuGet/Microsoft.Native.Quic.MsQuic.OpenSSL
  • NuGet/Microsoft.Native.Quic.MsQuic.Schannel
Microsoft QUIC: Remote Code Execution Vulnerability 08 Sep
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-23fw-v26w-5fgq
  • NuGet/Microsoft.Build.Tasks.Git
  • NuGet/Microsoft.SourceLink.AzureRepos.Git
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability 08 Sep
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-cvhv-g4rq-3hmw
  • NuGet/Magick.NET-Q16-AnyCPU
  • NuGet/Magick.NET-Q16-HDRI-AnyCPU
  • NuGet/Magick.NET-Q16-HDRI-OpenMP-arm64
  • NuGet/Magick.NET-Q16-HDRI-arm64
  • NuGet/Magick.NET-Q16-HDRI-x64
  • ... 12 more
ImageMagick: Memory Leak when providing invalid options to the cli 02 Sep
  • Fix available
  • Severity - 3.3 (Low)