{"id":"GHSA-g4vj-cjjj-v7hg","aliases":[],"url":"https://o3.security/vulnerability/GHSA-g4vj-cjjj-v7hg","summary":"Defense in Depth update for NuGet Client","details":"### Impact\nThis update adds validation of the package ID and version during package download, in addition to the existing package signature validation.\n\n### Patches\n\n#### NuGet\n\nThe following NuGet.exe, NuGet.CommandLine, NuGet.Packaging, and NuGet.Protocol versions have been patched:\n\n|Affected versions|Patched version|\n|--|--|\n|>= 4.9.0, <= 4.9.6|4.9.7|\n|>= 5.11.0, <= 5.11.6|5.11.7|\n|>= 6.8.0, <= 6.8.1|6.8.2|\n|>= 6.11.0, <= 6.11.1|6.11.2|\n|>= 6.12.0, <= 6.12.4|6.12.5|\n|>= 6.14.0, <= 6.14.2|6.14.3|\n|>= 7.0.0, <= 7.0.2|7.0.3|\n|7.3.0|7.3.1|\n\n#### .NET SDK\n\n* .NET 8.0.126 SDK\n* .NET 8.0.420 SDK\n* .NET 9.0.116 SDK\n* .NET 9.0.313 SDK\n* .NET 10.0.106 SDK\n* .NET 10.0.202 SDK\n\n### Workarounds\nN/A\n\n### References\nhttps://github.com/NuGet/NuGetGallery/security/advisories/GHSA-9r3h-v4hx-rhfr\n\n### Credit\n[splitline](https://x.com/_splitline_) with [DEVCORE](https://devco.re/)","published":"2026-04-14T23:42:30Z","modified":"2026-09-10T03:50:48.975042212Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"NuGet.Packaging","fixedVersion":"4.9.7"},{"ecosystem":"NuGet","name":"NuGet.Packaging","fixedVersion":"5.11.7"},{"ecosystem":"NuGet","name":"NuGet.Packaging","fixedVersion":"6.8.2"},{"ecosystem":"NuGet","name":"NuGet.Packaging","fixedVersion":"6.11.2"},{"ecosystem":"NuGet","name":"NuGet.Packaging","fixedVersion":"6.12.5"},{"ecosystem":"NuGet","name":"NuGet.Packaging","fixedVersion":"6.14.3"},{"ecosystem":"NuGet","name":"NuGet.Packaging","fixedVersion":"7.0.3"},{"ecosystem":"NuGet","name":"NuGet.Packaging","fixedVersion":"7.3.1"},{"ecosystem":"NuGet","name":"NuGet.Protocol","fixedVersion":"4.9.7"},{"ecosystem":"NuGet","name":"NuGet.Protocol","fixedVersion":"5.11.7"},{"ecosystem":"NuGet","name":"NuGet.Protocol","fixedVersion":"6.8.2"},{"ecosystem":"NuGet","name":"NuGet.Protocol","fixedVersion":"6.11.2"},{"ecosystem":"NuGet","name":"NuGet.Protocol","fixedVersion":"6.12.5"},{"ecosystem":"NuGet","name":"NuGet.Protocol","fixedVersion":"6.14.3"},{"ecosystem":"NuGet","name":"NuGet.Protocol","fixedVersion":"7.0.3"},{"ecosystem":"NuGet","name":"NuGet.Protocol","fixedVersion":"7.3.1"},{"ecosystem":"NuGet","name":"NuGet.CommandLine","fixedVersion":"4.9.7"},{"ecosystem":"NuGet","name":"NuGet.CommandLine","fixedVersion":"5.11.7"},{"ecosystem":"NuGet","name":"NuGet.CommandLine","fixedVersion":"6.8.2"},{"ecosystem":"NuGet","name":"NuGet.CommandLine","fixedVersion":"6.11.2"},{"ecosystem":"NuGet","name":"NuGet.CommandLine","fixedVersion":"6.12.5"},{"ecosystem":"NuGet","name":"NuGet.CommandLine","fixedVersion":"6.14.3"},{"ecosystem":"NuGet","name":"NuGet.CommandLine","fixedVersion":"7.0.3"},{"ecosystem":"NuGet","name":"NuGet.CommandLine","fixedVersion":"7.3.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/NuGet/NuGet.Client/security/advisories/GHSA-g4vj-cjjj-v7hg"},{"type":"WEB","url":"https://github.com/NuGet/NuGetGallery/security/advisories/GHSA-9r3h-v4hx-rhfr"},{"type":"PACKAGE","url":"https://github.com/NuGet/NuGet.Client"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:48.975042212Z"}}