| Cross-site Scripting (XSS) | |
| Missing Authorization | |
| GHSA-86r3-q889-hvg2 | |
| GHSA-35pc-qwv6-4858 | |
| GHSA-g9g2-qc64-jgcj | |
| GHSA-6fhj-cgmm-xfx6 | |
| GHSA-45h8-qrqh-xr5v | |
| Incorrect Authorization | |
| GHSA-94p8-87ff-w336 | |
| Exposure of Sensitive Information Through Metadata | |
| GHSA-2rc9-8cx9-fxpr | |
| GHSA-8jc8-cvqj-p926 | |
| Incorrect Authorization | |
| Missing Authorization | |
| Information Exposure | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| GHSA-hrxh-6v49-42gf | |
| GHSA-ff52-ph69-cf7x | |
| CVE-2026-42505 | |
| Authorization Bypass Through User-Controlled Key | |
| GHSA-r82j-g6q9-mvx8 | |
| GHSA-cx4g-hr74-m89m | |
| GHSA-c4m8-pv9j-v7mm | |
| Cross-site Scripting (XSS) | |
| GHSA-5cr4-qwvx-32j2 | |
| GHSA-7mq5-3vcf-v96v | |
| Allocation of Resources Without Limits or Throttling | |
| Incorrect Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| GHSA-q9j8-24p8-jq8j | |
| Improper Neutralization | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-hm74-p2xf-rqgc | |
| GHSA-w879-237q-wc7r | |
| GHSA-qpw4-5x99-6vjp | |
| GHSA-rm3j-f69w-wqmq | |
| GHSA-89gr-r52h-f8rx | |
| GHSA-vgwf-h737-ff37 | |
| GHSA-q4h4-gmj2-qvw2 | |
| Uncontrolled Memory Allocation | |
| GHSA-5wrp-cwcj-q835 | |
| CVE-2026-42504 | |
| GHSA-4279-q6mj-392r | |
| GHSA-h3gm-q7m7-mp28 | |
| GHSA-w2q5-6q6x-x959 | |
| GHSA-h524-452v-82p9 | |
| CVE-2026-27145 | |
| CVE-2026-39821 | |
| CVE-2026-42507 | |
| Out-of-Bounds | |
| Improper Verification of Cryptographic Signature | |
| Missing Authorization | |
| Improper Enforcement of Message Integrity During Transmission in a Communication Channel | |
| Incorrect Authorization | |
| GHSA-wgq9-qp63-g8j3 | |
| Integer Overflow or Wraparound | |
| Incorrect Type Conversion or Cast | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-r38r-hvg8-xqhf | |
| GHSA-5p55-qcqv-882w | |
| Use of Incorrectly-Resolved Name or Reference | |