gitsafehub
github.com/icsharpcode/ilspy ↗

icsharpcode/ilspy

scanned 2026-07-18 · git c40c299
2 of 6 checks flagged a security issue
🟡 Worth a look
6 checks ran. Start with vulnerable dependencies below.

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies12Known OSS vulnerabilities12Risky code patternsMalicious dependenciesProject health5

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 12 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2026-48109 MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48109). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48506 MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48506). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-48924 MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2024-48924). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48509 MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48509). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48510 MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48510). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48511 MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48511). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48512 MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48512). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48513 MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48513). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48514 MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48514). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48515 MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48515). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48516 MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-48517 MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
    ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48517). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 12 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing GHSA-2f33-pr97-265q MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48509). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2x83-8g95-xh59 MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48511). Fix: Update that package to its patched version.
  • Worth fixing GHSA-cj9g-3mj2-g8vv MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48512). Fix: Update that package to its patched version.
  • Worth fixing GHSA-cxmj-83gh-fp49 MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48515). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hv8m-jj95-wg3x MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48109). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q2h6-ghwm-5qm8 MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48516). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qhmf-xw27-6rqr MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48517). Fix: Update that package to its patched version.
  • Worth fixing GHSA-v72x-2h86-7f8m MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48510). Fix: Update that package to its patched version.
  • Worth fixing GHSA-vh6j-jc39-fggf MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48506). Fix: Update that package to its patched version.
  • Worth fixing GHSA-w567-gjr2-hm5j MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48514). Fix: Update that package to its patched version.
  • Worth fixing GHSA-wfr3-xj75-pfwh MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2026-48513). Fix: Update that package to its patched version.
  • FYI GHSA-4qm4-8hg2-g2xm MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
    /workdirs/scan-21ce85a2-e815-42a1-a71f-a9b208c79698/ILSpy.AddIn.VS2022/packages.lock.json
    A package you depend on has a known security hole (CVE-2024-48924). Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard 5 notes

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

  • Minor scorecard-overall OpenSSF Scorecard overall: 6.7/10
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Fuzzing Fuzzing scored 0: project is not fuzzed
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Pinned-Dependencies Pinned-Dependencies scored 0: dependency not pinned by hash detected -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Signed-Releases Signed-Releases scored 0: Project has not signed or included provenance with any releases.
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.

via OpenSSF Scorecard v5.5.0 · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.