All 5 CVE vulnerabilities found in NuGetGallery, with AI-generated Chinese analysis, references, and POCs.
Vendor: Microsoft
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-39399 | NuGet Gallery: Arbitrary Blob Overwrite via Nuspec Confusion and URI Fragment Truncation CWE-20 | 9.6 | Critical | 2026-04-14 |
| CVE-2024-54138 | XSS Vulnerability in NuGetGallery's Markdown Autolinks Processing CWE-79 | 5.4 | - | 2024-12-06 |
| CVE-2024-47604 | XSS vulnerability in NuGetGallery HTML attributes handling CWE-79 | 8.2 | High | 2024-10-01 |
| CVE-2024-37304 | NuGetGallery's Markdown Autolinks Processing Vulnerable to Cross-site Scripting CWE-79 | 6.1 | Medium | 2024-06-12 |
| CVE-2020-1340 | Microsoft NuGetGallery 跨站脚本漏洞 | 5.4 | - | 2020-06-09 |
All 5 known CVE vulnerabilities affecting NuGetGallery with full Chinese analysis, references, and POCs where available.