| Directory Traversal | |
| CVE-2026-2950 | |
| Improper Input Validation | |
| GHSA-26pp-8wgv-hjvm | |
| Directory Traversal | |
| CVE-2026-39412 | |
| CRLF Injection | |
| Inefficient Regular Expression Complexity | |
| Symlink Following | |
| Directory Traversal | |
| Resource Exhaustion | |
| Directory Traversal | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| GHSA-vvjj-xcjg-gr5g | |
| CVE-2026-4800 | |
| GHSA-458j-xx4x-4375 | |
| Resource Exhaustion | |
| GHSA-r4q5-vmmm-2653 | |
| GHSA-6v7q-wjvx-w8wg | |
| Information Exposure | |
| Arbitrary Code Injection | |
| GHSA-39q2-94rc-95cp | |
| HTTP Response Splitting | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Cross-site Scripting (XSS) | |
| CVE-2026-41650 | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| GHSA-w5hq-g745-h8pq | |
| CVE-2026-41311 | |
| CVE-2026-33458 | |
| CVE-2026-33459 | |
| CVE-2026-33460 | |
| CVE-2026-33461 | |
| CVE-2026-4498 | |
| Improper Input Validation | |
| Improper Input Validation | |
| Resource Exhaustion | |
| Improper Validation of Specified Quantity in Input | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| GHSA-cj63-jhhr-wcxv | |
| GHSA-cjmm-f4jc-qw8r | |
| GHSA-h8r8-wccr-v5f2 | |
| CVE-2026-26940 | |
| CVE-2026-26939 | |
| Off-by-one Error | |
| CVE-2026-3449 | |
| Incorrect Authorization | |
| CVE-2026-1525 | |
| Directory Traversal | |
| CVE-2026-1526 | |
| CVE-2026-2581 | |
| Cross-site Scripting (XSS) | |
| Directory Traversal | |
| CVE-2026-1527 | |
| CVE-2026-1528 | |
| CVE-2026-2229 | |
| Directory Traversal | |
| CVE-2026-26938 | |
| Inefficient Regular Expression Complexity | |
| CVE-2026-26935 | |
| Algorithmic Complexity | |
| Buffer Overflow | |
| CVE-2026-26934 | |
| Directory Traversal | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| Directory Traversal | |
| Incorrect Regular Expression | |
| Inefficient Regular Expression Complexity | |
| OS Command Injection | |
| Inefficient Regular Expression Complexity | |
| OS Command Injection | |
| CVE-2026-2391 | |
| CVE-2026-2739 | |
| CVE-2026-2327 | |
| Improper Check for Unusual or Exceptional Conditions | |
| Race Condition | |
| GHSA-6475-r3vj-m8vf | |
| CVE-2025-13465 | |
| Improper Input Validation | |
| CVE-2025-15284 | |
| Server-Side Request Forgery (SSRF) | |
| OS Command Injection | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Deserialization of Untrusted Data | |