| GHSA-qwww-vcr4-c8h2 | |
| GHSA-38gx-cfqf-f652 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-hq66-cqwq-w95j | |
| CVE-2026-16633 | |
| GHSA-wrjc-x8rr-h8h6 | |
| GHSA-8j4g-w8fx-2239 | |
| GHSA-337j-9hxr-rhxg | |
| GHSA-mwp4-54f8-5fhr | |
| GHSA-jjmj-jmhj-qwj2 | |
| Improper Input Validation | |
| GHSA-4xrf-jv44-h6hh | |
| Inefficient Regular Expression Complexity | |
| CVE-2026-18446 | |
| Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | |
| Open Redirect | |
| GHSA-7p8r-x3mc-p8w7 | |
| Cross-site Scripting (XSS) | |
| Improper Input Validation | |
| Improper Input Validation | |
| GHSA-22jq-vg5j-6vgg | |
| GHSA-v2hh-gcrm-f6hx | |
| GHSA-45rx-2jwx-cxfr | |
| GHSA-c2j3-45gr-mqc4 | |
| GHSA-mwf2-3pr3-8698 | |
| Race Condition | |
| GHSA-f4gw-2p7v-4548 | |
| GHSA-jfj6-75fj-8934 | |
| GHSA-j3f2-48v5-ccww | |
| GHSA-hcpx-6fm6-wx23 | |
| GHSA-xj6q-8x83-jv6g | |
| GHSA-gcfj-64vw-6mp9 | |
| GHSA-r28c-9q8g-f849 | |
| CVE-2026-16221 | |
| GHSA-f88m-g3jw-g9cj | |
| GHSA-mmx7-hfxf-jppx | |
| GHSA-frvp-7c67-39w9 | |
| GHSA-w62v-xxxg-mg59 | |
| GHSA-jqh4-m9w3-8hp9 | |
| GHSA-42h9-826w-cgv3 | |
| GHSA-pmv8-rq9r-6j72 | |
| GHSA-xgm2-5f3f-mvvc | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Uncaught Exception | |
| GHSA-hvrm-45r6-mjfj | |
| Cross-site Scripting (XSS) | |
| Use of Less Trusted Source | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| GHSA-7q8q-rj6j-mhjq | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Protection Mechanism Failure | |
| Insufficient Comparison | |
| Trust Boundary Violation | |
| Uncontrolled Recursion | |
| GHSA-f38q-mgvj-vph7 | |
| GHSA-cmwh-pvxp-8882 | |
| GHSA-94rc-8x27-4472 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-wcpc-wj8m-hjx6 | |
| Uncontrolled Recursion | |
| Cross-site Scripting (XSS) | |
| GHSA-8988-4f7v-96qf | |
| Cross-site Scripting (XSS) | |
| GHSA-x4vx-rjvf-j5p4 | |
| GHSA-rp9w-3fw7-7cwq | |
| GHSA-gvmj-g25r-r7wr | |
| Cross-site Scripting (XSS) | |
| GHSA-r47g-fvhr-h676 | |
| GHSA-76mc-f452-cxcm | |
| GHSA-hpcv-96wg-7vj8 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-vxr8-fq34-vvx9 | |
| GHSA-p6gq-j5cr-w38f | |
| CVE-2026-56761 | |
| Improper Encoding or Escaping of Output | |
| GHSA-wgpf-jwqj-8h8p | |
| Insufficient Verification of Data Authenticity | |
| Directory Traversal | |
| GHSA-hmw2-7cc7-3qxx | |
| CVE-2026-12143 | |
| GHSA-j6c9-x7qj-28xf | |
| Overly Permissive Cross-domain Whitelist | |
| GHSA-wwfh-h76j-fc44 | |
| Use of Less Trusted Source | |
| GHSA-88fw-hqm2-52qc | |
| GHSA-rv63-4mwf-qqc2 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-654m-c8p4-x5fp | |
| GHSA-35jp-ww65-95wh | |
| GHSA-898c-q2cr-xwhg | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-pjwm-pj3p-43mv | |
| HTTP Response Splitting | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| GHSA-jggg-4jg4-v7c6 | |
| Uncontrolled Recursion | |
| Improper Handling of Exceptional Conditions | |
| Arbitrary Code Injection | |
| GHSA-848j-6mx2-7j84 | |
| Arbitrary Code Injection | |
| GHSA-ghcm-xqfw-q4vr | |
| Arbitrary Code Injection | |
| Arbitrary Code Injection | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Improper Input Validation | |
| CVE-2026-41149 | |
| GHSA-3644-q5cj-c5c7 | |
| CVE-2025-14505 | |
| GHSA-fx83-v9x8-x52w | |
| GHSA-q7rr-3cgh-j5r3 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-75px-5xx7-5xc7 | |
| GHSA-66ff-xgx4-vchm | |
| GHSA-xcj9-5m2h-648r | |
| Uncontrolled Recursion | |
| GHSA-q6x5-8v7m-xcrf | |
| GHSA-jvwf-75h9-cwgg | |
| Improper Handling of Unicode Encoding | |
| GHSA-87f9-hvmw-gh4p | |
| GHSA-6m6c-36f7-fhxh | |
| GHSA-685m-2w69-288q | |
| GHSA-2pr8-phx7-x9h3 | |
| Deserialization of Untrusted Data | |
| GHSA-3q49-cfcf-g5fm | |
| Information Exposure Through Caching | |
| Improper Validation of Specified Quantity in Input | |
| Arbitrary Code Injection | |
| GHSA-hm8q-7f3q-5f36 | |
| GHSA-p77w-8qqv-26rm | |
| GHSA-qp7p-654g-cw7p | |
| GHSA-j759-j44w-7fr8 | |
| XML Injection | |
| GHSA-w5hq-g745-h8pq | |
| Arbitrary Code Injection | |
| Out-of-bounds Write | |
| GHSA-f6ww-3ggp-fr8h | |
| GHSA-69xw-7hcm-h432 | |
| Resource Exhaustion | |
| XML Injection | |
| GHSA-9vqf-7f2p-gf9v | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-3w6x-2g7m-8v23 | |
| Cross-site Scripting (XSS) | |
| GHSA-q8qp-cvcw-x6jj | |
| GHSA-2v35-w6hq-6mfw | |
| GHSA-gh4j-gqv2-49f6 | |
| GHSA-v2v4-37r5-5v8g | |
| XML Injection | |
| GHSA-x6wf-f3px-wcqx | |
| Uncontrolled Recursion | |
| XML Injection | |
| Information Exposure | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Arbitrary Code Injection | |
| CVE-2026-39410 | |
| Directory Traversal | |
| GHSA-xq3m-2v4x-88gg | |
| GHSA-r4q5-vmmm-2653 | |
| Directory Traversal | |
| GHSA-xpcf-pg52-r92g | |
| GHSA-fvcv-3m26-pcqx | |
| GHSA-3p68-rc4w-qgx5 | |
| GHSA-fw9q-39r9-c252 | |
| GHSA-458j-xx4x-4375 | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| GHSA-39q2-94rc-95cp | |
| GHSA-92pp-h63x-v22m | |
| CVE-2026-2950 | |
| GHSA-r5fr-rjxr-66jc | |
| Directory Traversal | |
| GHSA-rr7j-v2q5-chgv | |
| HTTP Response Splitting | |
| GHSA-vvjj-xcjg-gr5g | |
| GHSA-f23m-r3pf-42rh | |
| GHSA-xf4j-xp2r-rqqx | |
| GHSA-r5rp-j6wh-rvv4 | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| GHSA-wmmm-f939-6g9c | |
| GHSA-jvff-x2qm-6286 | |
| CVE-2026-4800 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| GHSA-29qv-4j9f-fjw5 | |
| GHSA-26pp-8wgv-hjvm | |
| CVE-2026-1526 | |
| CVE-2026-1527 | |
| CVE-2026-2581 | |
| GHSA-v8w9-8mx6-g223 | |
| Improper Validation of Specified Quantity in Input | |
| Cross-site Scripting (XSS) | |
| Off-by-one Error | |
| Uncontrolled Recursion | |
| GHSA-gmq8-994r-jv83 | |
| GHSA-8gc5-j5rx-235r | |
| GHSA-jp2q-39xq-3w4g | |
| GHSA-rf6f-7fwh-wjgh | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| GHSA-2mjp-6q6p-2qxm | |
| GHSA-v9p9-hfj2-hcw8 | |
| CVE-2026-1528 | |
| GHSA-f269-vfmq-vjvj | |
| GHSA-25h7-pfq9-p65f | |
| GHSA-phc3-fgpg-7m6h | |
| GHSA-vrm6-8vpv-qv8q | |
| GHSA-5v7r-6r5c-r473 | |
| GHSA-mr9r-mww3-v6gv | |
| GHSA-qj8w-gfj5-8c6v | |
| CVE-2026-2229 | |
| Resource Exhaustion | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-4992-7rv2-5pvq | |
| CVE-2026-1525 | |
| Inappropriate Comment Style | |
| Improper Handling of URL Encoding (Hex Encoding) | |
| GHSA-w7fw-mjwx-w883 | |
| GHSA-5pq2-9x2x-5p6w | |
| CVE-2026-2391 | |
| Arbitrary Code Injection | |
| GHSA-p6xx-57qc-3wxr | |
| GHSA-q5qw-h33p-qvwr | |
| GHSA-xpqw-6gx7-v673 | |
| GHSA-v2wj-7wpq-c8vv | |
| Direct Request ('Forced Browsing') | |
| GHSA-wc8c-qw6v-h7f6 | |
| Incorrect Authorization | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| GHSA-vpq2-c234-7xj6 | |
| GHSA-ph5j-38mg-j6hp | |
| Server-Side Request Forgery (SSRF) | |
| CVE-2026-3449 | |
| GHSA-rv83-g57w-fr8j | |
| GHSA-j3gx-2473-5fp8 | |
| GHSA-v34v-rq6j-cj6p | |
| Cross-site Scripting (XSS) | |
| GHSA-j4j7-vw47-rhfq | |
| GHSA-7hfw-r8qc-89v4 | |
| Improper Certificate Validation | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| GHSA-5c6j-r48x-rmvq | |
| Improper Certificate Validation | |
| GHSA-xf7r-hgr6-v32p | |
| CVE-2026-2359 | |
| GHSA-v52c-386h-88mc | |
| CVE-2026-3304 | |
| CVE-2026-3520 | |
| GHSA-5528-5vmv-3xc2 | |
| Algorithmic Complexity | |
| GHSA-7r86-cg39-jmmj | |
| Inefficient Regular Expression Complexity | |
| Directory Traversal | |
| GHSA-mw96-cpmx-2vgc | |
| CVE-2026-2739 | |
| GHSA-378v-28hj-76wf | |
| GHSA-gq3j-xvxp-8hrf | |
| GHSA-23c5-xmqv-rm74 | |
| GHSA-fj3w-jwp8-x2g3 | |
| Buffer Overflow | |
| Inefficient Regular Expression Complexity | |
| GHSA-3ppc-4f35-3m26 | |
| GHSA-2g4f-4pwh-qvx6 | |
| Inefficient Regular Expression Complexity | |
| GHSA-37qj-frw5-hhjh | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| Improper Input Validation | |
| GHSA-jmr7-xgp7-cmfj | |
| Server-Side Request Forgery (SSRF) | |
| Race Condition | |
| GHSA-8fgc-7cc6-rx7x | |
| GHSA-43fc-jf86-j433 | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-345p-7cg4-v4c7 | |
| GHSA-38r7-794h-5758 | |
| Improper Check for Unusual or Exceptional Conditions | |
| Inefficient Regular Expression Complexity | |
| Information Exposure Through Caching | |
| GHSA-6wqw-2p9w-4vw4 | |
| Information Exposure | |
| Cross-site Scripting (XSS) | |
| GHSA-7h2j-956f-4vf2 | |
| Improper Access Control | |
| GHSA-9r54-q6cx-xmh5 | |
| Incorrect Regular Expression | |
| GHSA-w332-q679-j88p | |
| GHSA-r354-f388-2fhh | |
| Improper Check or Handling of Exceptional Conditions | |
| Improper Authorization | |
| Improper Access Control | |
| Server-Side Request Forgery (SSRF) | |
| Resource Exhaustion | |
| GHSA-73rr-hh4g-fpgx | |
| GHSA-g9mf-h72j-4rw9 | |
| CVE-2025-13465 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-xxjr-mmjv-4gpg | |
| GHSA-8r9q-7v3j-jr4g | |
| Inefficient Regular Expression Complexity | |
| Improper Validation of Syntactic Correctness of Input | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-wqch-xfxh-vrr4 | |
| CVE-2025-13204 | |
| GHSA-6rw7-vpxm-498p | |
| CVE-2025-15284 | |
| GHSA-8gw3-rxh4-v6jx | |
| CVE-2025-13466 | |
| GHSA-r399-636x-v7f6 | |
| Deserialization of Untrusted Data | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Improper Input Validation | |
| Improper Verification of Cryptographic Signature | |
| GHSA-869p-cjfg-cm3x | |
| GHSA-w48q-cv73-mx4w | |
| Insecure Default Initialization of Resource | |
| GHSA-4fh9-h7wg-q85m | |
| CVE-2025-66400 | |
| GHSA-pj86-cfqh-vqx6 | |
| GHSA-rcmh-qjqh-p98v | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-mh29-5h37-fv8m | |
| Directory Traversal | |