VYPR
Medium severity5.9NVD Advisory· Published Aug 11, 2026· Updated Aug 14, 2026

CVE-2026-62900

CVE-2026-62900

Description

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.Build.Tasks.GitNuGet
>= 10.0.102, < 10.0.11110.0.111
Microsoft.Build.Tasks.GitNuGet
>= 10.0.200, <= 10.0.204—
Microsoft.Build.Tasks.GitNuGet
>= 10.0.300, < 10.0.30310.0.303
Microsoft.SourceLink.AzureRepos.GitNuGet
>= 10.0.102, < 10.0.11110.0.111
Microsoft.SourceLink.AzureRepos.GitNuGet
>= 10.0.200, <= 10.0.204—
Microsoft.SourceLink.AzureRepos.GitNuGet
>= 10.0.300, < 10.0.30310.0.303

Affected products

47

Patches

Vulnerability mechanics

References

4

News mentions

2