[{"id":"cms81knvvb2i3kh0clihaya5m","channel":"security","topic":"cve-published","title":"GHSA-cg4g-m8jx-vjv2","summary":"dssrf has an SSRF bypass with remove_at_symbol_in_string","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-cg4g-m8jx-vjv2","cvss":null,"cve_id":"GHSA-cg4g-m8jx-vjv2","source":"circl","summary":"dssrf has an SSRF bypass with remove_at_symbol_in_string","severity":null,"references":[{"url":"https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-cg4g-m8jx-vjv2","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54722","type":"ADVISORY"},{"url":"https://github.com/HackingRepo/dssrf-js/issues/97","type":"WEB"},{"url":"https://github.com/HackingRepo/dssrf-js/pull/98","type":"WEB"},{"url":"https://github.com/HackingRepo/dssrf-js/commit/9211f91bf532433a1a1b27d946571546a63664b3","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T21:44:48.620Z"},{"id":"cms7x9671b17nkh0cbuoxty7i","channel":"security","topic":"cve-published","title":"RUSTSEC-2026-0220","summary":"Uint shift operations: incorrect overflow flags and truncated shift amounts","payload":{"url":"https://www.cve.org/CVERecord?id=RUSTSEC-2026-0220","cvss":null,"cve_id":"RUSTSEC-2026-0220","source":"circl","summary":"Uint shift operations: incorrect overflow flags and truncated shift amounts","severity":null,"references":[{"url":"https://crates.io/crates/ruint","type":"PACKAGE"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0220.html","type":"ADVISORY"},{"url":"https://github.com/alloy-rs/ruint/pull/603","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T19:43:54.013Z"},{"id":"cms7v577nb0k1kh0cpyit4lwm","channel":"security","topic":"cve-published","title":"GHSA-h3qp-gqrc-q736","summary":"Spring Framework Open Redirect in Spring MVC and WebFlux","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-h3qp-gqrc-q736","cvss":null,"cve_id":"GHSA-h3qp-gqrc-q736","source":"circl","summary":"Spring Framework Open Redirect in Spring MVC and WebFlux","severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41844","type":"ADVISORY"},{"url":"https://github.com/spring-projects/spring-framework/commit/3aaec987651cf82fd4ed7e0ed9b3deddcdf58853","type":"WEB"},{"url":"https://github.com/spring-projects/spring-framework/commit/7add5243b9db13a9f8e765c8ab8545c8e8fe606b","type":"WEB"},{"url":"https://github.com/spring-projects/spring-framework","type":"PACKAGE"},{"url":"https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T18:44:49.475Z"},{"id":"cms7v56oib0jzkh0cjg11p5ax","channel":"security","topic":"cve-published","title":"GHSA-9f52-rjqv-25qv","summary":"Spring Framework Arbitrary Method Invocation in SpEL Expressions","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-9f52-rjqv-25qv","cvss":null,"cve_id":"GHSA-9f52-rjqv-25qv","source":"circl","summary":"Spring Framework Arbitrary Method Invocation in SpEL Expressions","severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41852","type":"ADVISORY"},{"url":"https://github.com/spring-projects/spring-framework","type":"PACKAGE"},{"url":"https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19","type":"WEB"},{"url":"https://github.com/spring-projects/spring-framework/releases/tag/v7.0.8","type":"WEB"},{"url":"https://spring.io/security/cve-2026-41852","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T18:44:48.786Z"},{"id":"cms7v564ab0jxkh0cwv2zu2wa","channel":"security","topic":"cve-published","title":"GHSA-xr9x-r78c-5hrm","summary":"Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-xr9x-r78c-5hrm","cvss":null,"cve_id":"GHSA-xr9x-r78c-5hrm","source":"circl","summary":"Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing","severity":null,"references":[{"url":"https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm","type":"WEB"},{"url":"https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e","type":"WEB"},{"url":"https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5","type":"WEB"},{"url":"https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a","type":"WEB"},{"url":"https://github.com/rails/rails","type":"PACKAGE"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T18:44:48.059Z"},{"id":"cms7oojdwayx9kh0cy1b466qp","channel":"security","topic":"cve-published","title":"GHSA-4hfh-6x8g-gwpp","summary":"Spring Framework Escalation via Session Fixation in WebFlux","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-4hfh-6x8g-gwpp","cvss":null,"cve_id":"GHSA-4hfh-6x8g-gwpp","source":"circl","summary":"Spring Framework Escalation via Session Fixation in WebFlux","severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41839","type":"ADVISORY"},{"url":"https://github.com/spring-projects/spring-framework/issues/36742","type":"WEB"},{"url":"https://github.com/spring-projects/spring-framework/issues/36743","type":"WEB"},{"url":"https://github.com/spring-projects/spring-framework/commit/b8ddd2c690fe3f00bb5e3d9f913a37504aab49a0","type":"WEB"},{"url":"https://github.com/spring-projects/spring-framework/commit/d72da90d3a562632e2b565113813f7b4a31f8717","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T15:43:54.404Z"},{"id":"cms7ooiuzayx7kh0cm3qi65i7","channel":"security","topic":"cve-published","title":"GHSA-83f7-v6px-pp3h","summary":"Spring Framework Denial of Service via Multipart Requests in WebFlux","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-83f7-v6px-pp3h","cvss":null,"cve_id":"GHSA-83f7-v6px-pp3h","source":"circl","summary":"Spring Framework Denial of Service via Multipart Requests in WebFlux","severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41840","type":"ADVISORY"},{"url":"https://github.com/spring-projects/spring-framework","type":"PACKAGE"},{"url":"https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19","type":"WEB"},{"url":"https://github.com/spring-projects/spring-framework/releases/tag/v7.0.8","type":"WEB"},{"url":"https://spring.io/security/cve-2026-41840","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T15:43:53.723Z"},{"id":"cms7kbyb7axrbkh0c9ay6s3p1","channel":"security","topic":"cve-published","title":"GHSA-w2q5-6q6x-x959","summary":"GHSA-w2q5-6q6x-x959","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-w2q5-6q6x-x959","cvss":null,"cve_id":"GHSA-w2q5-6q6x-x959","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","type":"ADVISORY"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:42142","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:42132","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:42082","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:08.755Z"},{"id":"cms7kbxsuaxr9kh0c4qms1rd7","channel":"security","topic":"cve-published","title":"GHSA-5pvg-856g-cp85","summary":"Netty has Insufficient Bailiwick Validation for NS Records","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-5pvg-856g-cp85","cvss":null,"cve_id":"GHSA-5pvg-856g-cp85","source":"circl","summary":"Netty has Insufficient Bailiwick Validation for NS Records","severity":null,"references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-5pvg-856g-cp85","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47691","type":"ADVISORY"},{"url":"https://access.redhat.com/errata/RHSA-2026:26017","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:26018","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:26586","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:08.094Z"},{"id":"cms7kbxamaxr7kh0cqv5ik33t","channel":"security","topic":"cve-published","title":"GHSA-676x-f7gg-47vc","summary":"Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-676x-f7gg-47vc","cvss":null,"cve_id":"GHSA-676x-f7gg-47vc","source":"circl","summary":"Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records","severity":null,"references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45674","type":"ADVISORY"},{"url":"https://access.redhat.com/errata/RHSA-2026:26017","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:26018","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:26586","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:07.438Z"},{"id":"cms7kbwsbaxr5kh0cefhi9ilf","channel":"security","topic":"cve-published","title":"GHSA-c2gf-v879-257j","summary":"netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-c2gf-v879-257j","cvss":null,"cve_id":"GHSA-c2gf-v879-257j","source":"circl","summary":"netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion","severity":null,"references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48043","type":"ADVISORY"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json","type":"WEB"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","type":"WEB"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:06.779Z"},{"id":"cms7kbw9saxr3kh0c22yhcmos","channel":"security","topic":"cve-published","title":"GHSA-h2qv-fj59-j46j","summary":"Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-h2qv-fj59-j46j","cvss":null,"cve_id":"GHSA-h2qv-fj59-j46j","source":"circl","summary":"Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion","severity":null,"references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-h2qv-fj59-j46j","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48059","type":"ADVISORY"},{"url":"https://access.redhat.com/errata/RHSA-2026:26017","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:26018","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:26586","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:06.112Z"},{"id":"cms7kbvrdaxr1kh0c2pmnkm9e","channel":"security","topic":"cve-published","title":"GHSA-5mx2-7g4j-9m39","summary":"GHSA-5mx2-7g4j-9m39","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-5mx2-7g4j-9m39","cvss":null,"cve_id":"GHSA-5mx2-7g4j-9m39","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55654","type":"ADVISORY"},{"url":"https://access.redhat.com/errata/RHSA-2026:36759","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:47756","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:47757","type":"WEB"},{"url":"https://access.redhat.com/security/cve/CVE-2026-55654","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:05.449Z"},{"id":"cms7kbv8yaxqzkh0c22om5e5b","channel":"security","topic":"cve-published","title":"GHSA-qcxp-gm7m-4j5v","summary":"Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-qcxp-gm7m-4j5v","cvss":null,"cve_id":"GHSA-qcxp-gm7m-4j5v","source":"circl","summary":"Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities","severity":null,"references":[{"url":"https://github.com/quarkusio/quarkus/security/advisories/GHSA-qcxp-gm7m-4j5v","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50559","type":"ADVISORY"},{"url":"https://github.com/quarkusio/quarkus/commit/919b80017d85564143a845b38e9cca54aff5b3cc","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:26017","type":"WEB"},{"url":"https://access.redhat.com/errata/RHSA-2026:26018","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:04.787Z"},{"id":"cms7kbuqnaxqxkh0crg9cyej0","channel":"security","topic":"cve-published","title":"GHSA-rmj7-2vxq-3g9f","summary":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-rmj7-2vxq-3g9f","cvss":null,"cve_id":"GHSA-rmj7-2vxq-3g9f","source":"circl","summary":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)","severity":null,"references":[{"url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513","type":"ADVISORY"},{"url":"https://github.com/FasterXML/jackson-databind/issues/5983","type":"WEB"},{"url":"https://github.com/FasterXML/jackson-databind/issues/5981","type":"WEB"},{"url":"https://github.com/FasterXML/jackson-databind/pull/5984","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:04.127Z"},{"id":"cms7kbu8aaxqvkh0cdhanyiwe","channel":"security","topic":"cve-published","title":"GHSA-4c8g-83qw-93j6","summary":"fast-uri vulnerable to host confusion via failed IDN canonicalization","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-4c8g-83qw-93j6","cvss":null,"cve_id":"GHSA-4c8g-83qw-93j6","source":"circl","summary":"fast-uri vulnerable to host confusion via failed IDN canonicalization","severity":null,"references":[{"url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13676","type":"ADVISORY"},{"url":"https://github.com/fastify/fast-uri/pull/188","type":"WEB"},{"url":"https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05","type":"WEB"},{"url":"https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bd","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:03.466Z"},{"id":"cms7kbtq2axqtkh0c69vbtp5k","channel":"security","topic":"cve-published","title":"GHSA-78ph-mc3q-52vv","summary":"GHSA-78ph-mc3q-52vv","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-78ph-mc3q-52vv","cvss":null,"cve_id":"GHSA-78ph-mc3q-52vv","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64560","type":"ADVISORY"},{"url":"https://git.kernel.org/stable/c/12a891c773aeb5823d63dbd0cb2ab931d6c21c9b","type":"WEB"},{"url":"https://git.kernel.org/stable/c/67aa823e3e8c229c6d374df79c804f6721cb83b6","type":"WEB"},{"url":"https://git.kernel.org/stable/c/6a7ecc25abe6f0fecc6e62a05096987200edbd02","type":"WEB"},{"url":"https://git.kernel.org/stable/c/920f893f735e92ba3a1cd9256899a186b161928d","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:02.810Z"},{"id":"cms7kbt7taxqrkh0c40xanac0","channel":"security","topic":"cve-published","title":"GHSA-p8vm-xf6w-g5jx","summary":"GHSA-p8vm-xf6w-g5jx","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-p8vm-xf6w-g5jx","cvss":null,"cve_id":"GHSA-p8vm-xf6w-g5jx","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4994","type":"ADVISORY"},{"url":"https://git.kernel.org/stable/c/dc7a4bfde507ffe1d8bef49aba1322f1d20c2cb3","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:02.153Z"},{"id":"cms7kbsphaxqpkh0cd3x0bnfn","channel":"security","topic":"cve-published","title":"GHSA-wm9c-mg5f-4mpg","summary":"GHSA-wm9c-mg5f-4mpg","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-wm9c-mg5f-4mpg","cvss":null,"cve_id":"GHSA-wm9c-mg5f-4mpg","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2395","type":"ADVISORY"},{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0608","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:01.493Z"},{"id":"cms7kbs7caxqnkh0c3fzsmgjk","channel":"security","topic":"cve-published","title":"GHSA-7wv8-chjv-grqm","summary":"GHSA-7wv8-chjv-grqm","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-7wv8-chjv-grqm","cvss":null,"cve_id":"GHSA-7wv8-chjv-grqm","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16970","type":"ADVISORY"},{"url":"https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260128-04_DFIR-IRIS_Insufficient_Logout","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:00.840Z"},{"id":"cms7kbrokaxqlkh0cn3vx3uw3","channel":"security","topic":"cve-published","title":"GHSA-fcp4-m28j-rjrq","summary":"GHSA-fcp4-m28j-rjrq","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-fcp4-m28j-rjrq","cvss":null,"cve_id":"GHSA-fcp4-m28j-rjrq","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16969","type":"ADVISORY"},{"url":"https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260126-01_DFIR-IRIS_Stored_XSS","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:42:00.164Z"},{"id":"cms7kbr64axqjkh0cjv3j0icb","channel":"security","topic":"cve-published","title":"GHSA-fxc2-748w-pcjx","summary":"GHSA-fxc2-748w-pcjx","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-fxc2-748w-pcjx","cvss":null,"cve_id":"GHSA-fxc2-748w-pcjx","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18360","type":"ADVISORY"},{"url":"https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260126-01_DFIR-IRIS_Stored_XSS","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:41:59.501Z"},{"id":"cms7kbqnraxqhkh0cj7jmhhde","channel":"security","topic":"cve-published","title":"GHSA-g3fm-cr7x-pwvj","summary":"GHSA-g3fm-cr7x-pwvj","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-g3fm-cr7x-pwvj","cvss":null,"cve_id":"GHSA-g3fm-cr7x-pwvj","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18369","type":"ADVISORY"},{"url":"https://access.redhat.com/security/cve/CVE-2026-18369","type":"WEB"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2509234","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:41:58.839Z"},{"id":"cms7kbq5caxqdkh0cnam7vqrs","channel":"security","topic":"cve-published","title":"GHSA-gj4w-mr87-6c67","summary":"GHSA-gj4w-mr87-6c67","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-gj4w-mr87-6c67","cvss":null,"cve_id":"GHSA-gj4w-mr87-6c67","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18361","type":"ADVISORY"},{"url":"https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260126-01_DFIR-IRIS_Stored_XSS","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:41:58.177Z"},{"id":"cms7kbpn2axqbkh0c93j7y8iw","channel":"security","topic":"cve-published","title":"GHSA-h2gf-gwxr-4pm4","summary":"GHSA-h2gf-gwxr-4pm4","payload":{"url":"https://www.cve.org/CVERecord?id=GHSA-h2gf-gwxr-4pm4","cvss":null,"cve_id":"GHSA-h2gf-gwxr-4pm4","source":"circl","summary":null,"severity":null,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18363","type":"ADVISORY"},{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/weak-password-recovery-mechanism-osticket-enhancesoft-llc","type":"WEB"}],"updated_at":null,"published_at":null},"public_metadata":null,"published_at":"2026-07-30T13:41:57.519Z"}]