Medium severity4.8NVD Advisory· Published Jul 17, 2026· Updated Aug 18, 2026
CVE-2026-55254
CVE-2026-55254
Description
NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src/NCalc.Core/Helpers/MathHelper.cs permits specially crafted expressions with extremely large factorial operands, causing excessive CPU consumption or a non-terminating loop due to integer overflow in the factorial calculation logic when applications evaluate untrusted expressions. This issue is fixed in version 6.1.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
NCalc.CoreNuGet | < 6.1.1 | 6.1.1 |
NCalcSyncNuGet | < 6.1.1 | 6.1.1 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/ncalc/ncalc/commit/eeb6155ee1899b1fdf2cda3da35a4f0ca93ffd6anvdPatch
- github.com/ncalc/ncalc/pull/575nvdIssue TrackingPatchWEB
- github.com/ncalc/ncalc/security/advisories/GHSA-3w5p-95mh-gq75nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-3w5p-95mh-gq75ghsaADVISORY
- github.com/ncalc/ncalc/releases/tag/v6.1.1nvdProductRelease Notes
News mentions
0No linked articles in our index yet.