| Cross-site Scripting (XSS) | |
| GHSA-jxrp-r7gx-q4j8 | |
| Resource Exhaustion | |
| GHSA-m8m8-qj5v-23w3 | |
| CVE-2026-101899 | |
| GHSA-542g-h47m-68v8 | |
| GHSA-r4gj-5m52-g5wh | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-j8rh-479h-cp32 | |
| Resource Exhaustion | |
| Arbitrary Code Injection | |
| GHSA-c29m-xwm3-cm6r | |
| Inefficient Regular Expression Complexity | |
| Arbitrary Code Injection | |
| GHSA-mghh-pgcx-3jjj | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-vh66-26gq-q6x8 | |
| GHSA-4hqw-qxg8-jxx2 | |
| GHSA-3pq3-5fj3-cg6v | |
| GHSA-44g4-m2mj-wpvx | |
| GHSA-qhr7-859c-m2p7 | |
| Resource Exhaustion | |
| GHSA-q2hr-2g5m-vwhr | |
| GHSA-6j4f-fj2g-mc7p | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Race Condition | |
| CVE-2026-84292 | |
| GHSA-vp7f-562j-4qgr | |
| CVE-2026-84394 | |
| GHSA-c3rm-3hqr-4qwm | |
| Use of Less Trusted Source | |
| GHSA-wr3r-jhmc-f6jw | |
| Incorrect Authorization | |
| GHSA-qw65-cvwx-89v3 | |
| GHSA-58mr-gqgx-xq4g | |
| Improper Validation of Array Index | |
| Directory Traversal | |
| GHSA-82fw-gwwq-j7x9 | |
| GHSA-2wm5-q62r-hmrv | |
| GHSA-2v4p-qf9q-27wj | |
| Inefficient Regular Expression Complexity | |
| GHSA-rx8g-88g5-qh64 | |
| CVE-2025-57352 | |
| Uncontrolled Recursion | |
| GHSA-3mcp-22mf-vrw3 | |
| GHSA-55q2-fjhq-7xh7 | |
| GHSA-fq2j-3j99-rx65 | |
| Cross-site Scripting (XSS) | |
| GHSA-c83g-rgw3-j3cx | |
| GHSA-38c4-r59v-3vqw | |
| GHSA-f23m-r3pf-42rh | |
| Algorithmic Complexity | |
| CVE-2026-82562 | |
| Exposed Dangerous Method or Function | |
| GHSA-378v-28hj-76wf | |
| GHSA-mh29-5h37-fv8m | |
| Resource Exhaustion | |
| GHSA-q8mj-m7cp-5q26 | |
| CVE-2026-14620 | |
| GHSA-qjx8-664m-686j | |
| GHSA-rp9w-3fw7-7cwq | |
| GHSA-r47g-fvhr-h676 | |
| GHSA-fqj3-h9pc-443h | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-37ch-88jc-xwx2 | |
| Inefficient Regular Expression Complexity | |
| Resource Exhaustion | |
| GHSA-67mh-4wv8-2f99 | |
| Cross-site Scripting (XSS) | |
| CVE-2026-12143 | |
| GHSA-h67p-54hq-rp68 | |
| GHSA-4mjr-xmp4-gh2g | |
| GHSA-42h9-826w-cgv3 | |
| Arbitrary Command Injection | |
| GHSA-xj6q-8x83-jv6g | |
| CVE-2026-12590 | |
| GHSA-jr5f-v2jv-69x6 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-73wf-gq98-2v4g | |
| GHSA-gvmj-g25r-r7wr | |
| CVE-2026-82417 | |
| GHSA-wf5p-g6vw-rhxx | |
| GHSA-5c6j-r48x-rmvq | |
| CVE-2026-9595 | |
| GHSA-hmw2-7cc7-3qxx | |
| Algorithmic Complexity | |
| Resource Exhaustion | |
| CVE-2025-13465 | |
| Improper Input Validation | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-6v5v-wf23-fmfq | |
| GHSA-23c5-xmqv-rm74 | |
| GHSA-wf6x-7x77-mvgw | |
| Server-Side Request Forgery (SSRF) | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-qj8w-gfj5-8c6v | |
| GHSA-76mc-f452-cxcm | |
| GHSA-mwf2-3pr3-8698 | |
| GHSA-f886-m6hf-6m8v | |
| Improper Encoding or Escaping of Output | |
| CVE-2024-4068 | |
| GHSA-vj76-c3g6-qr5v | |
| CVE-2026-3449 | |
| Resource Exhaustion | |
| GHSA-xvcm-6775-5m9r | |
| GHSA-v6h2-p8h4-qcjw | |
| Uncontrolled Recursion | |
| GHSA-64mm-vxmg-q3vj | |
| GHSA-952p-6rrq-rcjv | |
| GHSA-7mvr-c777-76hp | |
| GHSA-q7cg-457f-vx79 | |
| GHSA-jxxr-4gwj-5jf2 | |
| GHSA-r5fr-rjxr-66jc | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Protection Mechanism Failure | |
| CVE-2026-2327 | |
| GHSA-w9m9-85wc-3x92 | |
| GHSA-hcpx-6fm6-wx23 | |
| GHSA-9jgg-88mc-972h | |
| GHSA-5p4m-2wfm-xmqj | |
| CVE-2026-4867 | |
| GHSA-mh99-v99m-4gvg | |
| CVE-2026-45822 | |
| CVE-2026-56855 | |
| GHSA-qx2v-qp2m-jg93 | |
| CVE-2025-15284 | |
| GHSA-x4vx-rjvf-j5p4 | |
| Cross-site Scripting (XSS) | |
| Inefficient Regular Expression Complexity | |
| GHSA-96hv-2xvq-fx4p | |
| CVE-2026-14257 | |
| Directory Traversal | |
| Resource Exhaustion | |
| GHSA-7fh5-64p2-3v2j | |
| GHSA-5j98-mcp5-4vw2 | |
| GHSA-grv7-fg5c-xmjg | |
| Arbitrary Code Injection | |
| Origin Validation Error | |
| Improper Resource Shutdown or Release | |
| GHSA-pmv8-rq9r-6j72 | |
| GHSA-3ppc-4f35-3m26 | |
| Resource Exhaustion | |
| GHSA-jqh4-m9w3-8hp9 | |
| Resource Exhaustion | |
| Directory Traversal | |
| Algorithmic Complexity | |
| GHSA-76c9-3jph-rj3q | |
| GHSA-6g55-p6wh-862q | |
| GHSA-ph9p-34f9-6g65 | |
| External Control of File Name or Path | |
| GHSA-6hqm-hm2v-3p2p | |
| GHSA-vxr8-fq34-vvx9 | |
| CVE-2024-4067 | |
| Use of Uninitialized Resource | |
| GHSA-4x5r-pxfx-6jf8 | |
| Cross-site Scripting (XSS) | |
| GHSA-x5fp-wj9c-mxmx | |
| CVE-2026-4800 | |
| Uncaught Exception | |
| GHSA-v56q-mh7h-f735 | |
| Cross-site Scripting (XSS) | |
| Directory Traversal | |
| GHSA-7r86-cg39-jmmj | |
| GHSA-vp52-pcj8-j9qc | |
| Improper Verification of Cryptographic Signature | |
| GHSA-mx8g-39q3-5c79 | |
| GHSA-2g4f-4pwh-qvx6 | |
| Arbitrary Code Injection | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-m28w-2pqf-7qgj | |
| GHSA-vpq2-c234-7xj6 | |
| Algorithmic Complexity | |
| Algorithmic Complexity | |
| GHSA-mmx7-hfxf-jppx | |
| GHSA-v422-hmwv-36x6 | |
| Resource Exhaustion | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-8fgc-7cc6-rx7x | |
| GHSA-4ww2-rjh2-xpv9 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Uncaught Exception | |
| GHSA-r292-9mhp-454m | |
| Integer Overflow or Wraparound | |
| GHSA-4v9v-hfq4-rm2v | |
| GHSA-hpcv-96wg-7vj8 | |
| Inefficient Regular Expression Complexity | |
| CVE-2026-2739 | |
| Inefficient Regular Expression Complexity | |
| Out-of-bounds Write | |
| GHSA-rgw5-rvv9-x895 | |
| GHSA-r28c-9q8g-f849 | |
| GHSA-79cf-xcqc-c78w | |
| Information Exposure | |
| GHSA-52cp-r559-cp3m | |
| CVE-2026-13149 | |
| Directory Traversal | |
| Resource Exhaustion | |
| CVE-2026-2391 | |
| CVE-2026-78662 | |
| Directory Traversal | |
| CVE-2026-8723 | |
| GHSA-w7fw-mjwx-w883 | |
| CVE-2026-2950 | |
| GHSA-fv7c-fp4j-7gwp | |
| GHSA-v6wh-96g9-6wx3 | |
| GHSA-6rw7-vpxm-498p | |
| GHSA-p498-v437-472g | |
| GHSA-48c2-rrv3-qjmp | |
| GHSA-cmwh-pvxp-8882 | |
| GHSA-gcfj-64vw-6mp9 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-68jp-44vc-2x5h | |
| Directory Traversal | |
| Directory Traversal | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-8cj5-5rvv-wf4v | |
| GHSA-c27g-q93r-2cwf | |
| GHSA-9wx3-p993-35vp | |
| GHSA-v245-v573-v5vm | |
| GHSA-f5vj-f2hx-8m93 | |
| CVE-2026-6402 | |
| GHSA-c2j3-45gr-mqc4 | |
| CVE-2025-7339 | |
| GHSA-fxqj-rqcc-2cmp | |
| GHSA-f2r5-pqh9-r8f8 | |
| Resource Exhaustion | |
| Permissive Whitelist | |
| Cross-site Scripting (XSS) | |
| GHSA-rf6f-7fwh-wjgh | |
| GHSA-3jxr-9vmj-r5cp | |
| GHSA-vcc3-ghjq-m6fr | |
| GHSA-fx2h-pf6j-xcff | |
| GHSA-f4gw-2p7v-4548 | |
| GHSA-jmr9-qjv8-65gv | |
| GHSA-968p-4wvh-cqc8 | |
| OS Command Injection | |
| Resource Exhaustion | |
| GHSA-7q8q-rj6j-mhjq | |
| GHSA-xxjr-mmjv-4gpg | |
| Cross-site Scripting (XSS) | |
| Cross-site Request Forgery (CSRF) | |
| GHSA-58qx-3vcg-4xpx | |
| Resource Exhaustion | |
| Trust Boundary Violation | |
| GHSA-39j5-w47m-2gmv | |
| CVE-2026-56876 | |
| CVE-2026-14631 | |
| GHSA-38r7-794h-5758 | |
| GHSA-w5hq-g745-h8pq | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Directory Traversal | |
| GHSA-6gmq-8vp8-gcm6 | |
| GHSA-7p8r-x3mc-p8w7 | |
| GHSA-v39h-62p7-jpjc | |
| CVE-2026-75975 | |
| GHSA-f65p-4m7j-42xc | |
| CVE-2026-18446 | |
| CVE-2026-6322 | |
| CVE-2026-13676 | |
| GHSA-q3j6-qgpj-74h6 | |
| GHSA-v2hh-gcrm-f6hx | |
| GHSA-4c8g-83qw-93j6 | |
| GHSA-jqff-g426-hqxp | |
| CVE-2026-6321 | |
| CVE-2026-76172 | |
| CVE-2026-16221 | |
| GHSA-36jr-mh4h-2g58 | |
| GHSA-hc8v-wwc9-vgxm | |
| Link Following | |
| GHSA-qgq7-7hm3-q39j | |
| Directory Traversal | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-35jp-ww65-95wh | |
| GHSA-j5f8-grm9-p9fc | |
| Information Exposure | |
| GHSA-62hf-57xw-28j9 | |
| GHSA-xhjh-pmcv-23jw | |
| Resource Exhaustion | |
| GHSA-m7pr-hjqh-92cm | |
| Improper Check for Unusual or Exceptional Conditions | |
| HTTP Response Splitting | |
| GHSA-898c-q2cr-xwhg | |
| GHSA-r4q5-vmmm-2653 | |
| GHSA-3g43-6gmg-66jw | |
| Information Exposure | |
| Server-Side Request Forgery (SSRF) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-w9j2-pvgh-6h63 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-6chq-wfr3-2hj9 | |
| GHSA-445q-vr5w-6q77 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-5c9x-8gcm-mpgx | |
| Uncontrolled Recursion | |
| Improper Encoding or Escaping of Output | |
| GHSA-43fc-jf86-j433 | |
| GHSA-p92q-9vqr-4j8v | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-fvcv-3m26-pcqx | |
| Improper Authentication | |
| HTTP Response Splitting | |
| Permissive Whitelist | |
| GHSA-3w6x-2g7m-8v23 | |
| CRLF Injection | |
| GHSA-vf2m-468p-8v99 | |
| GHSA-hfxv-24rg-xrqf | |
| GHSA-pmwg-cvhr-8vh7 | |
| GHSA-4hjh-wcwx-xvwj | |
| GHSA-pf86-5x62-jrwf | |
| GHSA-3p68-rc4w-qgx5 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-xx6v-rp6x-q39c | |
| Allocation of Resources Without Limits or Throttling | |
| Arbitrary Code Injection | |
| Permissive Whitelist | |
| GHSA-q8qp-cvcw-x6jj | |
| GHSA-777c-7fjr-54vf | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| GHSA-xc2p-8ggw-6cr5 | |
| CVE-2026-56862 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| GHSA-25mv-j2qr-v5jq | |
| CVE-2026-56859 | |
| GHSA-28wg-ghj8-5hjv | |
| GHSA-2v37-7h3g-55p8 | |
| GHSA-7qch-w8m5-g3h3 | |
| CVE-2026-56860 | |
| GHSA-76p8-fhrm-vpc7 | |
| CVE-2026-33818 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-737v-mqg7-c878 | |
| CVE-2026-13311 | |
| GHSA-395f-4hp3-45gv | |
| Uncontrolled Recursion | |
| GHSA-25h7-pfq9-p65f | |
| XML Injection | |
| XML Injection | |
| Uncontrolled Recursion | |
| GHSA-f6ww-3ggp-fr8h | |
| GHSA-wh4c-j3r5-mjhp | |
| XML Injection | |
| XML Injection | |
| GHSA-j759-j44w-7fr8 | |
| GHSA-x6wf-f3px-wcqx | |
| GHSA-2v35-w6hq-6mfw | |
| Uncaught Exception | |
| GHSA-34x7-hfp2-rc4v | |
| Directory Traversal | |
| GHSA-9ppj-qmqm-q256 | |
| Directory Traversal | |
| GHSA-8x88-c5mf-7j5w | |
| GHSA-r6q2-hw4h-h46w | |
| GHSA-vmf3-w455-68vh | |
| GHSA-gvwx-54wh-qm9j | |
| Incorrect Type Conversion or Cast | |
| GHSA-qffp-2rhf-9h96 | |
| GHSA-w8wr-v893-vjvp | |
| GHSA-83g3-92jg-28cx | |
| GHSA-8qq5-rm4j-mr97 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | |
| Directory Traversal | |
| Interpretation Conflict | |
| Directory Traversal | |
| Directory Traversal | |
| GHSA-23hp-3jrh-7fpw | |
| Improper Handling of Unicode Encoding | |
| GHSA-xv26-6w52-cph6 | |
| GHSA-mp7j-qc5w-4988 | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Handling of Length Parameter Inconsistency | |
| CVE-2025-12816 | |
| Improper Verification of Cryptographic Signature | |
| Uncontrolled Recursion | |
| GHSA-5m6q-g25r-mvwx | |
| Improper Input Validation | |
| GHSA-65ch-62r8-g69g | |
| Integer Overflow or Wraparound | |
| GHSA-ppp5-5v6c-4jwp | |
| GHSA-2328-f5f3-gj25 | |
| Improper Certificate Validation | |
| GHSA-554w-wpv2-vw27 | |
| GHSA-q67f-28xg-22rw | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| GHSA-5gfm-wpxj-wjgq | |
| GHSA-22p9-wv53-3rq4 | |
| Inefficient Regular Expression Complexity | |
| GHSA-w7jw-789q-3m8p | |
| CVE-2026-9277 | |
| GHSA-w5pp-99ch-qj29 | |
| GHSA-crhj-59gh-8x96 | |
| Improper Encoding or Escaping of Output | |
| GHSA-xhf5-7wjv-pqxp | |
| GHSA-c2c7-rcm5-vvqj | |
| Improper Input Validation | |
| Inefficient Regular Expression Complexity | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-47262 | |
| GHSA-m7cr-m3pv-hgrp | |
| GHSA-3v7f-55p6-f55p | |
| Directory Traversal | |
| GHSA-jpcc-p29g-p8mq | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| GHSA-p9ff-h696-f583 | |
| GHSA-5xrq-8626-4rwp | |
| Directory Traversal | |
| GHSA-v2wj-q39q-566r | |
| Directory Traversal | |
| GHSA-4w7w-66w2-5vf9 | |
| Information Exposure | |
| GHSA-pjwm-pj3p-43mv | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-7rx3-28cr-v5wh | |
| Arbitrary Code Injection | |
| Arbitrary Code Injection | |
| GHSA-xjpj-3mr7-gcpf | |
| Improper Check for Unusual or Exceptional Conditions | |
| GHSA-xhpv-hc6g-r9c6 | |
| GHSA-3mfm-83xf-c92r | |
| GHSA-442j-39wm-28r2 | |
| GHSA-2qvq-rjwj-gvw9 | |
| Arbitrary Code Injection | |
| GHSA-9cx6-37pm-9jff | |
| Cross-site Scripting (XSS) | |
| GHSA-2w6w-674q-4c4q | |
| Cross-site Scripting (XSS) | |
| CVE-2025-6545 | |
| CVE-2025-6547 | |
| GHSA-v62p-rq8g-8h59 | |
| GHSA-h7cp-r72f-jxh6 | |
| Symlink Following | |
| GHSA-rgh6-rfwx-v388 | |
| GHSA-84xv-jfrm-h4gm | |
| CVE-2026-50195 | |
| CVE-2025-7783 | |
| GHSA-33vj-92qq-66hc | |
| Improper Input Validation | |
| GHSA-cvxm-645q-p574 | |
| GHSA-fjxv-7rqg-78g4 | |
| Directory Traversal | |
| GHSA-cpq7-6gpm-g9rc | |
| CVE-2025-9287 | |
| GHSA-95m3-7q98-8xr5 | |
| CVE-2025-9288 | |