| Algorithmic Complexity | |
| GHSA-528h-pc64-c93x | |
| GHSA-h3hj-cmcx-xc66 | |
| External Control of File Name or Path | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Permissive Whitelist | |
| GHSA-fq2j-3j99-rx65 | |
| GHSA-39j5-w47m-2gmv | |
| Information Exposure | |
| GHSA-9wx3-p993-35vp | |
| Resource Exhaustion | |
| GHSA-fqj3-h9pc-443h | |
| Resource Exhaustion | |
| GHSA-68jp-44vc-2x5h | |
| GHSA-6hqm-hm2v-3p2p | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-8657 | |
| GHSA-j4fx-xxwh-2485 | |
| Resource Exhaustion | |
| GHSA-4ww2-rjh2-xpv9 | |
| GHSA-f2r5-pqh9-r8f8 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| Directory Traversal | |
| Insufficient Verification of Data Authenticity | |
| Improper Input Validation | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| GHSA-2v37-7h3g-55p8 | |
| GHSA-28wg-ghj8-5hjv | |
| GHSA-38gx-cfqf-f652 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-5p4m-2wfm-xmqj | |
| GHSA-vpq2-c234-7xj6 | |
| Algorithmic Complexity | |
| GHSA-jqh4-m9w3-8hp9 | |
| GHSA-f88m-g3jw-g9cj | |
| GHSA-4c39-4ccg-62r3 | |
| GHSA-q8wf-6r8g-63ch | |
| GHSA-7q8q-rj6j-mhjq | |
| Excessive Iteration | |
| GHSA-r28c-9q8g-f849 | |
| Information Exposure Through Caching | |
| GHSA-j3f2-48v5-ccww | |
| Information Exposure | |
| Open Redirect | |
| GHSA-x445-f3h2-j279 | |
| GHSA-68g3-v927-f742 | |
| GHSA-xj6q-8x83-jv6g | |
| GHSA-4633-3j49-mh5q | |
| GHSA-gcfj-64vw-6mp9 | |
| GHSA-mmx7-hfxf-jppx | |
| GHSA-7rqj-j65f-68wh | |
| CVE-2026-3449 | |
| GHSA-f4gw-2p7v-4548 | |
| GHSA-8r6m-32jq-jx6q | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-m99w-x7hq-7vfj | |
| GHSA-89xv-2m56-2m9x | |
| GHSA-p9j2-gv94-2wf4 | |
| GHSA-42h9-826w-cgv3 | |
| GHSA-955p-x3mx-jcvp | |
| GHSA-hcpx-6fm6-wx23 | |
| Improper Encoding or Escaping of Output | |
| GHSA-mwf2-3pr3-8698 | |
| GHSA-pmv8-rq9r-6j72 | |
| GHSA-xmf8-cvqr-rfgj | |
| Server-Side Request Forgery (SSRF) | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Directory Traversal | |
| GHSA-45h5-66jx-r2wf | |
| GHSA-p6gq-j5cr-w38f | |
| Uncontrolled Recursion | |
| GHSA-99f4-grh7-6pcq | |
| GHSA-5375-pq7m-f5r2 | |
| CVE-2026-12143 | |
| GHSA-f38q-mgvj-vph7 | |
| Uncaught Exception | |
| GHSA-hmw2-7cc7-3qxx | |
| Uncaught Exception | |
| GHSA-898c-q2cr-xwhg | |
| HTTP Response Splitting | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-35jp-ww65-95wh | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| GHSA-654m-c8p4-x5fp | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-pjwm-pj3p-43mv | |
| GHSA-jggg-4jg4-v7c6 | |
| GHSA-26hh-7cqf-hhc6 | |
| Uncontrolled Recursion | |
| Authentication Bypass | |
| GHSA-w5hq-g745-h8pq | |
| Out-of-bounds Write | |
| Cross-site Scripting (XSS) | |
| GHSA-qx2v-qp2m-jg93 | |
| HTTP Response Splitting | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-3w6x-2g7m-8v23 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-pmwg-cvhr-8vh7 | |
| Allocation of Resources Without Limits or Throttling | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| GHSA-vf2m-468p-8v99 | |
| Improper Authentication | |
| GHSA-q8qp-cvcw-x6jj | |
| GHSA-pf86-5x62-jrwf | |
| GHSA-m7pr-hjqh-92cm | |
| GHSA-445q-vr5w-6q77 | |
| Uncontrolled Recursion | |
| GHSA-xhjh-pmcv-23jw | |
| GHSA-6chq-wfr3-2hj9 | |
| GHSA-w9j2-pvgh-6h63 | |
| GHSA-62hf-57xw-28j9 | |
| Permissive Whitelist | |
| CRLF Injection | |
| GHSA-xx6v-rp6x-q39c | |
| Improper Encoding or Escaping of Output | |
| Permissive Whitelist | |
| GHSA-5c9x-8gcm-mpgx | |
| Server-Side Request Forgery (SSRF) | |
| Arbitrary Code Injection | |
| GHSA-xq3m-2v4x-88gg | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| HTTP Response Splitting | |
| GHSA-vvjj-xcjg-gr5g | |
| GHSA-fvcv-3m26-pcqx | |
| GHSA-3p68-rc4w-qgx5 | |
| GHSA-q4gf-8mx6-v5v3 | |
| GHSA-38f7-945m-qr2g | |
| GHSA-f23m-r3pf-42rh | |
| GHSA-c7w3-x93f-qmm8 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-r5fr-rjxr-66jc | |
| CVE-2026-4800 | |
| CVE-2026-2950 | |
| GHSA-737v-mqg7-c878 | |
| Race Condition | |
| GHSA-3x4c-7xq6-9pq8 | |
| Resource Exhaustion | |
| CVE-2026-2229 | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| GHSA-2mjp-6q6p-2qxm | |
| GHSA-v9p9-hfj2-hcw8 | |
| CVE-2026-1526 | |
| GHSA-vrm6-8vpv-qv8q | |
| GHSA-8gc5-j5rx-235r | |
| GHSA-phc3-fgpg-7m6h | |
| HTTP Request Smuggling | |
| GHSA-f269-vfmq-vjvj | |
| GHSA-4992-7rv2-5pvq | |
| CVE-2026-2581 | |
| CVE-2026-1528 | |
| CVE-2026-1527 | |
| CVE-2026-1525 | |
| GHSA-ggv3-7p47-pfv8 | |
| GHSA-pxg6-pf52-xh8x | |
| GHSA-554w-wpv2-vw27 | |
| GHSA-5gfm-wpxj-wjgq | |
| GHSA-33vc-wfww-vjfv | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-mwv6-3258-q52c | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-76p3-8jx3-jpfq | |
| CVE-2024-47764 | |
| GHSA-5jpx-9hw9-2fx4 | |
| GHSA-f82v-jwr5-mffw | |
| CVE-2025-66478 | |
| GHSA-4hjh-wcwx-xvwj | |
| CVE-2024-55565 | |
| CVE-2025-59472 | |
| GHSA-fj3w-jwp8-x2g3 | |
| GHSA-4342-x723-ch2f | |
| CVE-2025-22871 | |
| Information Exposure Through Caching | |
| GHSA-g9mf-h72j-4rw9 | |
| GHSA-mm7p-fcc7-pg87 | |
| GHSA-mwcw-c2x4-8c55 | |
| Incorrect Authorization | |
| GHSA-9qr9-h5gf-34mp | |
| GHSA-5f7q-jpqc-wp7h | |
| GHSA-rcmh-qjqh-p98v | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-8cj5-5rvv-wf4v | |
| CVE-2025-7783 | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| Inefficient Regular Expression Complexity | |
| Authorization Bypass Through User-Controlled Key | |
| Improper Validation of Syntactic Correctness of Input | |
| GHSA-37qj-frw5-hhjh | |
| GHSA-pfq8-rq6v-vf5m | |
| Improper Check for Unusual or Exceptional Conditions | |
| GHSA-968p-4wvh-cqc8 | |
| CVE-2025-9910 | |
| GHSA-xxjr-mmjv-4gpg | |
| GHSA-r2fc-ccr8-96c4 | |
| CVE-2025-13465 | |
| Improper Input Validation | |
| Buffer Overflow | |
| GHSA-fjxv-7rqg-78g4 | |
| Uncontrolled Recursion | |
| GHSA-gp8f-8m3g-qvj9 | |
| Inefficient Regular Expression Complexity | |
| Use of Insufficiently Random Values | |
| Uncontrolled Recursion | |
| GHSA-mh29-5h37-fv8m | |
| Improper Input Validation | |
| GHSA-c76h-2ccp-4975 | |
| GHSA-jmr7-xgp7-cmfj | |
| GHSA-g77x-44xx-532m | |
| GHSA-xv57-4mr9-wg8v | |
| Integer Overflow or Wraparound | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-43fc-jf86-j433 | |
| GHSA-jr5f-v2jv-69x6 | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-g9pc-8g42-g6vq | |
| GHSA-7m27-7ghc-44w9 | |
| GHSA-w37m-7fhw-fmv9 | |
| Improper Verification of Cryptographic Signature | |
| Server-Side Request Forgery (SSRF) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-g5qg-72qw-gw5v | |
| CVE-2025-12816 | |
| GHSA-869p-cjfg-cm3x | |
| HTTP Request Smuggling | |
| Improper Check or Handling of Exceptional Conditions | |
| Directory Traversal | |
| GHSA-65ch-62r8-g69g | |
| Server-Side Request Forgery (SSRF) | |
| CVE-2024-34351 | |
| CVE-2024-37168 | |