CVE-2026-39399
A security flaw in the NuGet Gallery backend allows attackers to inject malicious metadata through specially crafted package files. This vulnerability stems from insufficient validation of input within.nuspec files and package identifiers.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users or administrators managing the NuGet Gallery backend service.
Real-world impact
An attacker could potentially execute remote code or write arbitrary data to storage containers. This could allow them to tamper with existing content within the repository.
Why this severity
The critical score reflects that an attacker can remotely exploit this via a network connection with low complexity, potentially leading to full system compromise through code execution or unauthorized data writes.
What to do about it
- 01Apply the patch provided in commit 0e80f87628349207cdcaf55358491f8a6f1ca276.
NVD-referenced vendor advisory
Timeline
- Apr 14, 2026 · Apr 14, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.