| GHSA-395f-4hp3-45gv | |
| CVE-2026-13311 | |
| GHSA-36jr-mh4h-2g58 | |
| Resource Exhaustion | |
| GHSA-62hf-57xw-28j9 | |
| GHSA-p92q-9vqr-4j8v | |
| Permissive Whitelist | |
| Permissive Whitelist | |
| GHSA-43fc-jf86-j433 | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| GHSA-w9j2-pvgh-6h63 | |
| GHSA-898c-q2cr-xwhg | |
| GHSA-m7pr-hjqh-92cm | |
| GHSA-xx6v-rp6x-q39c | |
| GHSA-hfxv-24rg-xrqf | |
| GHSA-35jp-ww65-95wh | |
| Server-Side Request Forgery (SSRF) | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| GHSA-pmwg-cvhr-8vh7 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Information Exposure | |
| GHSA-777c-7fjr-54vf | |
| GHSA-3w6x-2g7m-8v23 | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-4hjh-wcwx-xvwj | |
| GHSA-j5f8-grm9-p9fc | |
| CRLF Injection | |
| HTTP Response Splitting | |
| GHSA-3g43-6gmg-66jw | |
| Arbitrary Code Injection | |
| GHSA-vf2m-468p-8v99 | |
| GHSA-q8qp-cvcw-x6jj | |
| GHSA-xhjh-pmcv-23jw | |
| GHSA-r4q5-vmmm-2653 | |
| Improper Encoding or Escaping of Output | |
| Improper Check for Unusual or Exceptional Conditions | |
| GHSA-3p68-rc4w-qgx5 | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| HTTP Response Splitting | |
| GHSA-fvcv-3m26-pcqx | |
| GHSA-445q-vr5w-6q77 | |
| Information Exposure | |
| GHSA-pf86-5x62-jrwf | |
| Uncontrolled Recursion | |
| GHSA-6chq-wfr3-2hj9 | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-5c9x-8gcm-mpgx | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improper Authentication | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| GHSA-2v37-7h3g-55p8 | |
| GHSA-28wg-ghj8-5hjv | |
| XML Injection | |
| GHSA-j759-j44w-7fr8 | |
| GHSA-wh4c-j3r5-mjhp | |
| Uncontrolled Recursion | |
| XML Injection | |
| GHSA-2v35-w6hq-6mfw | |
| GHSA-x6wf-f3px-wcqx | |
| XML Injection | |
| XML Injection | |
| GHSA-f6ww-3ggp-fr8h | |
| GHSA-2m8v-j782-fhvr | |
| Improper Input Validation | |
| GHSA-w8wr-v893-vjvp | |
| Improper Handling of Unicode Encoding | |
| Directory Traversal | |
| GHSA-vmf3-w455-68vh | |
| GHSA-9ppj-qmqm-q256 | |
| Incorrect Type Conversion or Cast | |
| GHSA-gvwx-54wh-qm9j | |
| Uncaught Exception | |
| GHSA-83g3-92jg-28cx | |
| Directory Traversal | |
| CVE-2026-56859 | |
| GHSA-25mv-j2qr-v5jq | |
| GHSA-qffp-2rhf-9h96 | |
| Allocation of Resources Without Limits or Throttling | |
| Directory Traversal | |
| GHSA-8qq5-rm4j-mr97 | |
| GHSA-xc2p-8ggw-6cr5 | |
| GHSA-r6q2-hw4h-h46w | |
| GHSA-23hp-3jrh-7fpw | |
| Directory Traversal | |
| GHSA-34x7-hfp2-rc4v | |
| GHSA-8x88-c5mf-7j5w | |
| GHSA-76p8-fhrm-vpc7 | |
| CVE-2026-56860 | |
| Interpretation Conflict | |
| CVE-2026-33818 | |
| Directory Traversal | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| CVE-2026-56862 | |
| GHSA-7qch-w8m5-g3h3 | |
| GHSA-qgq7-7hm3-q39j | |
| Link Following | |
| Directory Traversal | |
| GHSA-hc8v-wwc9-vgxm | |
| Uncontrolled Recursion | |
| GHSA-25h7-pfq9-p65f | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-737v-mqg7-c878 | |