Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
.NET
MessagePack-CSharp
Uncontrolled Recursion
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium
.NET
MessagePack-CSharp
Allocation of Resources Without Limits or Throttling
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium
.NET
MessagePack-CSharp
Allocation of Resources Without Limits or Throttling
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium
.NET
MessagePack-CSharp
Inefficient Algorithmic Complexity
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium
.NET
MessagePack-CSharp
Deserialization of Untrusted Data
Use of Externally-Controlled Input to Select Classes or Code
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Low
.NET
.NET SDK
Insufficient Verification of Data Authenticity
.NET SDK >= 6.0.0 <= 6.0.41
Jul 29, 2026
High
Jackson
jackson-databind
Authorization Bypass
>=2.15.0 <2.18.8, >=2.19.0 <2.21.4
Jul 29, 2026
High
Quarkus
Quarkus
Authorization Bypass
<3.20.6.1, >=3.21.0 <3.27.3.1, >=3.30.0 <3.33.1.1, >=3.34.0 <3.35.1.1
Jul 29, 2026
Medium
Quarkus
Quarkus
Denial of Service
<3.20.5, >=3.21.0 <3.27.2, >=3.30.0 <3.31.0
Jul 29, 2026
Critical
Quarkus
Quarkus
Authorization Bypass
>=2.9.0.CR1 <3.8.6.1, >=3.9.0.CR1 <3.15.3.1, >=3.16.0.CR1 <3.18.0.CR1
Jul 29, 2026
High
Quarkus
Quarkus
Information Exposure
<3.2.12.Final, >=3.3.0.CR1 <=3.8.3, >=3.9.0.CR1 <=3.9.1
Jul 29, 2026
High
Next.js
Next.js
Server-Side Request Forgery
URL Redirect/Open Redirect
>=12.0.0 <15.5.21, >=16.0.0 <16.2.11
Jul 24, 2026
Critical
Ingress NGINX
NGINX (ngx_http_proxy_v2_module and ngx_http_grpc_module); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Heap-based Buffer Overflow
NGINX Open Source 1.13.10 through 1.31.1; NGINX Plus R33 through R37.0.1; Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
Critical
Ingress NGINX
NGINX (script engine, map directive); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Heap-based Buffer Overflow
NGINX Open Source 0.9.6 through 1.31.2 (map regex support introduced in 0.9.6, 2011); Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
Medium
Ingress NGINX
NGINX (ngx_http_charset_module); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Buffer Over-read
Information Disclosure
NGINX Open Source 0.3.50 through 1.31.1; Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
