CVE-2017-9785: Deserialization of Untrusted Data in NancyFX Nancy

Severity: Critical

CVSS Score: 9.8

Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.