{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-08-09T10:13:23.532584+00:00",
  "immutable_run": true,
  "item_count": 20,
  "items": [
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71399/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22871,
      "epss_score": 0.00306,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2025-71399",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2025-71399.json",
      "product": null,
      "public_safe_summary": "NVD: Better Auth relies on better-call, which uses the rou3 router library. NVD: In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. NVD: In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2025-71399.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Better Auth relies on better-call, which uses the rou3 router library. NVD: In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. NVD: In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71399/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71400/",
      "current_public_safe_latest": true,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10308,
      "epss_score": 0.00202,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2025-71400",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2025-71400.json",
      "product": null,
      "public_safe_summary": "NVD: better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. NVD: Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys. OSV: better-auth passkey before 1.4.0 IDOR via delete-passkey",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2025-71400.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. NVD: Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys. OSV: better-auth passkey before 1.4.0 IDOR via delete-passkey",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71400/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71401/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17577,
      "epss_score": 0.0026,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2025-71401",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2025-71401.json",
      "product": null,
      "public_safe_summary": "NVD: better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). NVD: An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to return 404 for all users (denial of service). NVD: The issue is not reachable when baseURL is explicitly configured or on typical managed hosting platforms.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2025-71401.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). NVD: An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to return 404 for all users (denial of service). NVD: The issue is not reachable when baseURL is explicitly configured or on typical managed hosting platforms.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71401/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67356/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15837,
      "epss_score": 0.00246,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-67356",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67356.json",
      "product": null,
      "public_safe_summary": "NVD: ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. NVD: Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-67356.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. NVD: Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67356/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67357/",
      "current_public_safe_latest": true,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16365,
      "epss_score": 0.0025,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-67357",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67357.json",
      "product": null,
      "public_safe_summary": "NVD: ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. NVD: Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-67357.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. NVD: Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67357/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68578/",
      "current_public_safe_latest": true,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1179,
      "epss_score": 0.00214,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68578",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68578.json",
      "product": null,
      "public_safe_summary": "NVD: ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. NVD: Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68578.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. NVD: Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68578/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68579/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18791,
      "epss_score": 0.00269,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68579",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68579.json",
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). NVD: When an OLE paste consumer (e.g. NVD: explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the server-supplied length (req_fsize) instead of cb.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68579.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). NVD: When an OLE paste consumer (e.g. NVD: explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the server-supplied length (req_fsize) instead of cb.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68579/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68580/",
      "current_public_safe_latest": true,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14802,
      "epss_score": 0.00238,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68580",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68580.json",
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. NVD: Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms. OSV: FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68580.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. NVD: Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms. OSV: FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68580/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68581/",
      "current_public_safe_latest": true,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24561,
      "epss_score": 0.00321,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68581",
      "impact_tags": [
        "authentication boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68581.json",
      "product": null,
      "public_safe_summary": "NVD: Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. NVD: Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tokens endpoints. NVD: An authenticated attacker can obtain a target's numeric user ID via authenticated user search, then create link shares on an attacker-writable project until the link-share sequence reaches that value, and use the resulting link-share JWT to list, create, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68581.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. NVD: Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tokens endpoints. NVD: An authenticated attacker can obtain a target's numeric user ID via authenticated user search, then create link shares on an attacker-writable project until the link-share sequence reaches that value, and use the resulting link-share JWT to list, create, and...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68581/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68582/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.11369,
      "epss_score": 0.00211,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68582",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68582.json",
      "product": null,
      "public_safe_summary": "NVD: Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). NVD: The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. NVD: For a link-share token holder, the task scope is pinned to the share's own project, but the view is taken from the attacker-controlled path and never re-validated.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68582.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 2.4.0..",
      "source_published_summary": "NVD: Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). NVD: The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. NVD: For a link-share token holder, the task scope is pinned to the share's own project, but the view is taken from the attacker-controlled path and never re-validated.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68582/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68583/",
      "current_public_safe_latest": true,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03629,
      "epss_score": 0.00138,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68583",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68583.json",
      "product": null,
      "public_safe_summary": "NVD: luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68583.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68583/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10774/",
      "current_public_safe_latest": true,
      "cvss_score": 2.4,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04835,
      "epss_score": 0.00152,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-10774",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-10774.json",
      "product": null,
      "public_safe_summary": "NVD: Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. NVD: In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but subnet_keys_destroy() guarded the matching psa_destroy_key() with CONFIG_BT_MESH_V1d1. NVD: That Kconfig symbol was removed when explicit Mesh 1.0.1 support was dropped, so the destroy branch became permanently dead code and the import is never balanced by a destroy.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-10774.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. NVD: In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but subnet_keys_destroy() guarded the matching psa_destroy_key() with CONFIG_BT_MESH_V1d1. NVD: That Kconfig symbol was removed when explicit Mesh 1.0.1 support was dropped, so the destroy branch became permanently dead code and the import is never balanced by a destroy.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10774/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65321/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.37349,
      "epss_score": 0.00455,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-65321",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-65321.json",
      "product": null,
      "public_safe_summary": "NVD: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the... NVD: Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via... OSV: PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-65321.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the... NVD: Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via... OSV: PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65321/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9856/",
      "current_public_safe_latest": true,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21738,
      "epss_score": 0.00295,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-9856",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-9856.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. NVD: The issue resides in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin, where keys from the chat_template dictionary are used directly as filenames without proper validation. NVD: An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted tokenizer_config.json file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-9856.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. NVD: The issue resides in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin, where keys from the chat_template dictionary are used directly as filenames without proper validation. NVD: An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted tokenizer_config.json file.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9856/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10848/",
      "current_public_safe_latest": true,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09438,
      "epss_score": 0.00195,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-10848",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-10848.json",
      "product": null,
      "public_safe_summary": "NVD: The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1... NVD: Because strncpy does not NUL-terminate the destination when the source is at least outlen - 1 (127) bytes long, the subsequent strchr reads past the 128-byte destination buffer into adjacent stack memory; if a \" byte is found beyond the buffer, a one-byte... NVD: A related defect in extract_payload() runs strchr/strrchr over the receive buffer, which may not be NUL-terminated when a maximal-length frame fills it.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-10848.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1... NVD: Because strncpy does not NUL-terminate the destination when the source is at least outlen - 1 (127) bytes long, the subsequent strchr reads past the 128-byte destination buffer into adjacent stack memory; if a \" byte is found beyond the buffer, a one-byte... NVD: A related defect in extract_payload() runs strchr/strrchr over the receive buffer, which may not be NUL-terminated when a maximal-length frame fills it.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10848/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "n-able / n-central",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18577/",
      "current_public_safe_latest": true,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.89787,
      "epss_score": 0.04103,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-18577",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": true,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18577.json",
      "product": "n-central",
      "public_safe_summary": "NVD: An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 CISA KEV: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-18577.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n-able / n-central; affected version context: 2026.3",
      "source_published_impact": "Source describes known exploited catalog listed · authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for known exploited catalog listed · authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 CISA KEV: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
      "sources": [
        "NVD",
        "CISA KEV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18577/timeline.json",
      "vendor": "n-able"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3245/",
      "current_public_safe_latest": true,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15177,
      "epss_score": 0.00241,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-3245",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-3245.json",
      "product": null,
      "public_safe_summary": "NVD: A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-3245.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3245/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12185/",
      "current_public_safe_latest": true,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17897,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-12185",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-12185.json",
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12. OSV: BKS/UBER keystore allocates from untrusted lengths before integrity check",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-12185.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12. OSV: BKS/UBER keystore allocates from untrusted lengths before integrity check",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12185/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15055/",
      "current_public_safe_latest": true,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17899,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-15055",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15055.json",
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-15055.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15055/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18581/",
      "current_public_safe_latest": true,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01588,
      "epss_score": 0.00112,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-18581",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18581.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in ggml-org llama.cpp e15efe0. NVD: Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. NVD: Executing a manipulation with the input {{9|9|{ can lead to reachable assertion.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-18581.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in ggml-org llama.cpp e15efe0. NVD: Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. NVD: Executing a manipulation with the input {{9|9|{ can lead to reachable assertion.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18581/timeline.json",
      "vendor": null
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20260809T101323Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}