Report a CVE to HeroDevs

Committed to Security and Confidentiality

At HeroDevs, safeguarding the security of open-source software and its ecosystem is our priority. As a Certified Numbering Authority (CNA), we ensure your vulnerability reports are handled with utmost confidentiality and professionalism.

Search tool icon

Report a Vulnerability

When you report a CVE, you can trust that:
  • Your submission is reviewed promptly and securely by our team of security experts.
  • Details of the vulnerability will not be disclosed until appropriate patches are developed and coordinated with the necessary stakeholders.
  • Your role as the reporter will be respected, with attribution provided as per your preference.
Every vulnerability we address strengthens the open-source ecosystem and ensures the continued security of end-of-life software. At HeroDevs, we actively track, assess, and address vulnerabilities to safeguard the security of open source software and protect the businesses that rely on it.

By clicking “submit” I acknowledge receipt of our Privacy Policy.

Thank you! Your submission has been received!
Please enter a company email.
Early Detection and CVE Remediation

187 Security Issues Fixed
(and always looking for more)

Below is a snapshot of the most recent 10 of 75 vulnerabilities in our database, demonstrating our commitment to transparency and proactive security.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
.NET
Azure Identity library for .NET (Azure.Identity)
Insufficiently Protected Credentials
Azure.Identity < 1.11.0
Jul 29, 2026
Medium
.NET
Azure Identity library for .NET
Concurrent Execution using Shared Resource with Improper Synchronization
Azure.Identity < 1.11.4
Jul 29, 2026
High
.NET
.NET (System.Text.Json)
Inefficient Algorithmic Complexity
System.Text.Json >= 6.0.0 < 6.0.10; System.Text.Json >= 8.0.0 < 8.0.5
Jul 29, 2026
High
.NET
MessagePack-CSharp
Use of Weak Hash
MessagePack < 2.5.187; MessagePack >= 2.6.95-alpha < 3.0.214-rc.1; NES Essentials Plus MessagePack fork (2.5.192.x): not affected.
Jul 29, 2026
High
.NET
MessagePack-CSharp
Improper Input Validation (4.16)
MessagePack < 2.5.301; MessagePack >= 3.0.214-rc.1 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.2
Jul 29, 2026
High
.NET
MessagePack-CSharp
Uncontrolled Recursion
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.2
Jul 29, 2026
Medium
.NET
MessagePack-CSharp
Initialization of a Resource with an Insecure Default
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium
.NET
MessagePack-CSharp
Allocation of Resources Without Limits or Throttling
Improper Handling of Highly Compressed Data (Data Amplification)
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.2
Jul 29, 2026
Medium
.NET
MessagePack-CSharp
Inefficient Algorithmic Complexity
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium
.NET
MessagePack-CSharp
Uncontrolled Recursion
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
For more details on CVEs found in end-of-life software, visit our vulnerability directory.