CVE-2026-39399Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply a crafted nuspec file with malicious metadata, leading to cross package metadata injection that may result in remote code execution (RCE) and/or arbitrary blob writes due to insufficient input validation. The issue is exploitable via URI fragment injection using unsanitized package identifiers, allowing an attacker to control the resolved blob path. This enables writes to arbitrary blobs within the storage container, not limited to .nupkg files, resulting in potential tampering of existing content. This issue has been patched in commit 0e80f87628349207cdcaf55358491f8a6f1ca276.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-04-15)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-14: 1Mentions · 2026-04-15: 4Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 304-1404-15
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-154
Disclosure3General1
Full discourse5 posts
  • IntegSec@integ_sec
    General

    CVE-2026-39399: NuGetGallery Input Validation Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04c9J7p0

    Post summary

    The excerpt merely lists the CVE identifier and a link, with no detailed information on the vulnerability, exploitation, or mitigations.

    0000023
    28 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Metadata Injection in #NuGetGallery. CVE-2026-39399 CVSS: 9.6. This vulnerability can lead to remote code execution #RCE and arbitrary blob writes! #Patch #Patch #Patch

    Post summary

    The text announces CVE-2026-39399 in NuGetGallery, noting its high severity and potential for remote code execution, but provides no patch, PoC, or exploit details.

    00000145
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39399 NuGet Gallery is a package repository that powers http://nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet … https://www.cve.org/CVERecord?id=CVE-2026-39399

    Post summary

    The post announces CVE‑2026‑39399 as a vulnerability in NuGet Gallery’s processing of .nuspec files, but offers no details on exploitation, mitigation, or PoC.

    0000068
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39399 Cross Package Metadata Injection Leading to Remote Code Execution in NuGet Gallery https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39399

    Post summary

    The text references CVE‑2026‑39399, describing a metadata injection flaw in NuGet Gallery that permits remote code execution, but it provides no PoC, exploit, or patch details.

    0000047
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39399: NuGet Gallery: Arbitrary Blob Ov... URI fragment injection in .nuspec parsing lets attackers write arbitrary blobs to NuGet's storage—RCE through package m... https://zerodaysignal.com/vulnerability/CVE-2026-39399 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑39399, noting a URI fragment injection in NuGet Gallery’s .nuspec parsing that permits arbitrary blob writes and potential RCE, but it provides only high‑level vulnerability details without PoC, exploit code, or patch information.

    0000049
    218 followersView on X

Explore more