Microsoft.WindowsDesktop.App.Runtime.win-x64
HighNuGetCVE-2026-50646
What to do
Update Microsoft.WindowsDesktop.App.Runtime.win-x64 to 10.0.10 or later.
dotnet add package Microsoft.WindowsDesktop.App.Runtime.win-x64 --version 10.0.10
An unsafe deserialisation flaw affects the NuGet package Microsoft.WindowsDesktop.App.Runtime.win-x64. Affected versions: >= 10.0.0, <= 10.0.9. Fixed from version 10.0.10. CVSS score 7.8.
What the flaw allows: Attacker-crafted objects are rebuilt without validation.
- Package
- Microsoft.WindowsDesktop.App.Runtime.win-x64
- Ecosystem
- NuGet (.NET)
- Class
- Unsafe deserialisation
- Affected versions
- >= 10.0.0, <= 10.0.9
- CVSS
- 7.8
- Published on
- September 8, 2026
Sources
Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.