Trivy reports a false positive for CVE-2025-26646 / GHSA-h4j7-5rxr-p4wc
Command
trivy image mcr.microsoft.com/dotnet/sdk --scanners vuln --vuln-type library
Output

According to this discussion it's a false positive and 17.14.5 is not vulnerable
dotnet/msbuild#11846 (comment)
Nuget also does not report a vulnerability in 17.14.5
https://www.nuget.org/packages/Microsoft.Build.Tasks.Core/17.14.5