VDB

GHSA-32wq-ppwg-3w4m

GHSA-32wq-ppwg-3w4m PUBLISHED CVSS 7.5 HIGH

EnhancedLinq.Async is Vulnerable to Denial of Service via Transitive Dependency Microsoft.Bcl.Memory

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
NuGetMicrosoft.NetCore.App.Runtime.osx-x6410.0.0, 9.0.2, 9.0.3
NuGetMicrosoft.NetCore.App.Runtime.win-arm9.0.0, 10.0.0, 9.0.0
NuGetMicrosoft.Bcl.Memory9.0.8, 9.0.2, 9.0.3
NuGetMicrosoft.NetCore.App.Runtime.linux-x649.0.2, 9.0.13, 9.0.10
NuGetMicrosoft.NetCore.App.Runtime.win-x869.0.4, 9.0.9, 9.0.0
NuGetEnhancedLinq.Async1.0.0-beta.1, 1.0.0-beta.1, 1.0.0-beta.1
NuGetMicrosoft.NetCore.App.Runtime.linux-musl-arm649.0.0, 10.0.0, 10.0.0
NuGetMicrosoft.NetCore.App.Runtime.linux-arm10.0.0, 10.0.3, 9.0.13
NuGetMicrosoft.NetCore.App.Runtime.linux-arm649.0.0, 9.0.0, 9.0.12
NuGetMicrosoft.NetCore.App.Runtime.win-x649.0.11, 9.0.0, 9.0.0
NuGetMicrosoft.NetCore.App.Runtime.linux-musl-arm9.0.2, 9.0.0, 9.0.1
NuGetMicrosoft.NetCore.App.Runtime.linux-musl-x649.0.0, 9.0.1, 9.0.11
NuGetMicrosoft.NetCore.App.Runtime.osx-arm649.0.0, 9.0.0, 9.0.0
NuGetMicrosoft.NetCore.App.Runtime.win-arm649.0.7, 9.0.0, 9.0.10

Timeline

  • Mar 18, 2026 Security Advisory
  • Apr 1, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›