| CVE-2026-42499 | |
| Improper Encoding or Escaping of Output | |
| GHSA-qc64-m6c2-v4x7 | |
| GHSA-497x-jcxf-m478 | |
| GHSA-p9h5-jm8x-mjm5 | |
| GHSA-5m4p-2gjx-p2g8 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-8g2r-hhvj-mv99 | |
| GHSA-xq5j-9r39-c3vf | |
| GHSA-3v2c-x6q9-f697 | |
| GHSA-qf3q-3h68-mmh2 | |
| Double Free | |
| NULL Pointer Dereference | |
| Out-of-bounds Write | |
| Cross-site Scripting (XSS) | |
| GHSA-2283-wf8c-rw8r | |
| Link Following | |
| CVE-2026-42501 | |
| GHSA-h74g-238j-357m | |
| CVE-2026-39825 | |
| GHSA-pc3f-x583-g7j2 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-mh2q-q3fh-2475 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-hr2v-4r36-88hr | |
| Directory Traversal | |
| GHSA-5w89-2c2x-6x66 | |
| GHSA-m4pr-4j3g-9v7v | |
| GHSA-7mr4-xjxg-34g6 | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-32280 | |
| GHSA-gjvh-7jh8-7xhm | |
| Cross-site Scripting (XSS) | |
| GHSA-jrg3-gfjw-hm96 | |
| GHSA-x4jj-h2v8-hqqv | |
| Improper Certificate Validation | |
| Allocation of Resources Without Limits or Throttling | |
| Incorrect Authorization | |
| Uncaught Exception | |
| GHSA-78h2-9frx-2jm8 | |
| GHSA-p77j-4mvh-x3m3 | |
| Improper Authorization | |
| GHSA-j3gx-2473-5fp8 | |
| GHSA-rv83-g57w-fr8j | |
| GHSA-j4j7-vw47-rhfq | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Direct Request ('Forced Browsing') | |
| GHSA-h355-32pf-p2xm | |
| CVE-2025-61732 | |
| GHSA-8jvr-vh7g-f8gx | |
| CVE-2025-68121 | |
| GHSA-j5w8-q4qc-rx2x | |
| CVE-2025-58181 | |
| Memory Leak | |
| Incorrect Execution-Assigned Permissions | |
| Algorithmic Complexity | |
| Allocation of Resources Without Limits or Throttling | |
| Use of Uninitialized Resource | |
| Race Condition | |
| Arbitrary Code Injection | |