Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
NuGet
Package ecosystem NuGet. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
Totals
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 34 | 34 | 6 |
Monthly trend
▂▁▁█
2026-07 4 · 2026-08 0 · 2026-09 1 · 2026-10 29
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55969 | 8.7 | 62.6 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-47896 | 8.9 | 55.5 | — | Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator rep… |
| CVE-2026-47897 | 8.9 | 52.5 | — | Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator … |
| CVE-2026-86600 | 8.2 | 41.7 | — | Workload identity attestation generated before login host validation in Snowflake drivers |
| CVE-2026-47898 | 4.0 | 38.5 | — | Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser |
| CVE-2026-63567 | 8.2 | 38.4 | — | IesEngine block-cipher mode checks padding before MAC (CBC padding oracle) |
| CVE-2026-82458 | 8.7 | 34.8 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-103603 | 8.7 | 33.4 | — | Unbounded HSS public key level count allows huge array allocation during signature veri… |
| CVE-2026-63569 | 9.1 | 31.6 | — | MTI/A0 DHAgreement does not validate the peer's ephemeral value |
| CVE-2026-63566 | 8.7 | 29.0 | — | DTLS handshake reassembler allocates buffer from unchecked 24-bit length |
| CVE-2026-105239 | 5.3 | 25.1 | — | Apache log4net: NUL character truncates EventLogAppender records |
| CVE-2026-105241 | 5.3 | 25.1 | — | Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch |
| CVE-2026-105242 | 5.3 | 25.1 | — | Apache log4net: Request validation failure drops the event in the aspnet-request converter |
| CVE-2026-105244 | 5.3 | 25.1 | — | Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content |
| CVE-2026-105240 | 5.3 | 24.2 | — | Apache log4net: NUL character truncates OutputDebugStringAppender records |
| CVE-2026-105243 | 5.3 | 24.2 | — | Apache log4net: Oversize EventLogAppender record silently discarded |
| CVE-2026-63572 | 7.1 | 24.1 | — | Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files |
| CVE-2026-63578 | 7.1 | 24.1 | — | Unbounded PBE iteration count when decrypting PKCS#8 private keys |
| CVE-2026-63568 | 8.7 | 22.8 | — | Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion |
| CVE-2026-63574 | 8.7 | 22.4 | — | Unbounded allocation from OpenPGP signature and user attribute subpacket lengths |
Most-affected packages
| Package | CVEs |
|---|---|
| BouncyCastle.Cryptography | 21 |
| log4net | 6 |
| ApacheThrift | 3 |
| Lucene.Net.Replicator | 2 |
| Lucene.Net.Analysis.Common | 1 |
| Snowflake.Data | 1 |