Hi @sai.pabbareddy , I'm not really sure what question you're asking? CVE-2025-26646 has been in Inedo's database as PGV-2535204 since May 13, 2025. However, under the default risk profile in ProGet, we rate this a Category 1 since there is effectively no risk posed by this vulnerability. It requires a malicious inside actor with access to modify the source code -- which is not a realistic threat actor. As such, ProGet will not not "spam" developers via the NuGet client with needless warnings. This is all by design. You can learn more about that here: https://guides.inedo.com/vulnerability-management/categories/ Thanks, Alana