| GHSA-2v37-7h3g-55p8 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Directory Traversal | |
| GHSA-6g55-p6wh-862q | |
| GHSA-r28c-9q8g-f849 | |
| Directory Traversal | |
| CVE-2026-14257 | |
| Resource Exhaustion | |
| GHSA-f7vp-7xgx-4w4r | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| GHSA-v5mv-p594-2x33 | |
| GHSA-rgw5-rvv9-x895 | |
| GHSA-mh99-v99m-4gvg | |
| Cross-site Scripting (XSS) | |
| GHSA-fxqj-rqcc-2cmp | |
| GHSA-qx2v-qp2m-jg93 | |
| Directory Traversal | |
| GHSA-mqq9-gxg5-m58g | |
| Information Exposure | |
| Information Exposure | |
| GHSA-32rq-jhr7-m3hh | |
| Information Exposure | |
| GHSA-3fvr-2jw6-crq4 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-mjrx-74jh-7xgw | |
| CRLF Injection | |
| GHSA-wm3w-8rrp-j577 | |
| GHSA-f886-m6hf-6m8v | |
| GHSA-wpwq-4j6v-78m3 | |
| Resource Exhaustion | |
| GHSA-6chq-wfr3-2hj9 | |
| Allocation of Resources Without Limits or Throttling | |
| HTTP Response Splitting | |
| GHSA-445q-vr5w-6q77 | |
| Improper Authentication | |
| GHSA-42h9-826w-cgv3 | |
| Improper Input Validation | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| GHSA-3w6x-2g7m-8v23 | |
| GHSA-pmv8-rq9r-6j72 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-j5f8-grm9-p9fc | |
| GHSA-34xg-wgjx-8xph | |
| GHSA-3jxr-9vmj-r5cp | |
| GHSA-p92q-9vqr-4j8v | |
| Improper Check for Unusual or Exceptional Conditions | |
| GHSA-mmx7-hfxf-jppx | |
| Information Exposure | |
| GHSA-h95v-h523-3mw8 | |
| GHSA-f283-ghqc-fg79 | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Arbitrary Code Injection | |
| GHSA-3g43-6gmg-66jw | |
| GHSA-xhjh-pmcv-23jw | |
| HTTP Response Splitting | |
| GHSA-5c9x-8gcm-mpgx | |
| Permissive Whitelist | |
| GHSA-q8qp-cvcw-x6jj | |
| CVE-2026-13149 | |
| GHSA-xx6v-rp6x-q39c | |
| Origin Validation Error | |
| GHSA-7q8q-rj6j-mhjq | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Encoding or Escaping of Output | |
| GHSA-jqh4-m9w3-8hp9 | |
| CRLF Injection | |
| GHSA-mwf2-3pr3-8698 | |
| GHSA-vm85-hxw5-5432 | |
| Permissive Whitelist | |
| GHSA-vf2m-468p-8v99 | |
| GHSA-94pj-82f3-465w | |
| GHSA-hfxv-24rg-xrqf | |
| GHSA-hq7v-mx3g-29hw | |
| GHSA-cwxw-98qj-8qjx | |
| GHSA-35jp-ww65-95wh | |
| GHSA-g446-98w2-8p5w | |
| GHSA-pmwg-cvhr-8vh7 | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-43fc-jf86-j433 | |
| Uncontrolled Recursion | |
| GHSA-777c-7fjr-54vf | |
| GHSA-hmw2-7cc7-3qxx | |
| Information Exposure | |
| GHSA-r4q5-vmmm-2653 | |
| Resource Exhaustion | |
| Origin Validation Error | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Input Validation | |
| GHSA-pf86-5x62-jrwf | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Resource Exhaustion | |
| GHSA-62hf-57xw-28j9 | |
| GHSA-m7pr-hjqh-92cm | |
| GHSA-w9j2-pvgh-6h63 | |
| GHSA-fvcv-3m26-pcqx | |
| GHSA-898c-q2cr-xwhg | |
| GHSA-3p68-rc4w-qgx5 | |
| Missing Encryption of Sensitive Data | |
| CVE-2026-12143 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-v6h2-p8h4-qcjw | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-pjwm-pj3p-43mv | |
| GHSA-f7pm-6hr8-7ggm | |
| Origin Validation Error | |
| CVE-2025-14761 | |
| GHSA-x8cp-jf6f-r4xh | |
| Use of Non-Canonical URL Paths for Authorization Decisions | |
| GHSA-3rg7-wf37-54rm | |