CVE-2017-9785: Nancyfx Nancy

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.

Affected products

  • Nancyfx Nancy: up to and including 1.4.3; version 2.0.0 only

Published 2017-07-20. Last modified 2026-06-17.