{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-08-10T22:09:19.106897+00:00",
  "immutable_run": true,
  "item_count": 20,
  "items": [
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10849/",
      "current_public_safe_latest": true,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20198,
      "epss_score": 0.0028,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-10849",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-10849.json",
      "product": "zephyr",
      "public_safe_summary": "NVD: The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). NVD: The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. NVD: When the full response has arrived, the code writes response_data[downloaded_size] = '\\0' — and whenever the accumulated body length equals the allocation, that terminator lands one byte past the end of the heap object (a heap-based out-of-bounds write...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-10849.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). NVD: The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. NVD: When the full response has arrived, the code writes response_data[downloaded_size] = '\\0' — and whenever the accumulated body length equals the allocation, that terminator lands one byte past the end of the heap object (a heap-based out-of-bounds write...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10849/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18682/",
      "current_public_safe_latest": true,
      "cvss_score": 1.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.15975,
      "epss_score": 0.00247,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-18682",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18682.json",
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in OpenAkita up to 1.27.12. NVD: This vulnerability affects unknown code of the file /api/upload of the component File Upload API. NVD: The manipulation of the argument File results in cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-18682.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in OpenAkita up to 1.27.12. NVD: This vulnerability affects unknown code of the file /api/upload of the component File Upload API. NVD: The manipulation of the argument File results in cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18682/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46712/",
      "current_public_safe_latest": true,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11964,
      "epss_score": 0.00215,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-46712",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-46712.json",
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. NVD: This vulnerability occurs whether or not federation is enabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-46712.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. NVD: This vulnerability occurs whether or not federation is enabled.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46712/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46713/",
      "current_public_safe_latest": true,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.07052,
      "epss_score": 0.00174,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-46713",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-46713.json",
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. NVD: This issue has been fixed in version 2026.5.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-46713.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. NVD: This issue has been fixed in version 2026.5.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46713/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46714/",
      "current_public_safe_latest": true,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17892,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-46714",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-46714.json",
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. NVD: This issue has been fixed in version 2026.5.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-46714.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. NVD: This issue has been fixed in version 2026.5.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46714/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47746/",
      "current_public_safe_latest": true,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07979,
      "epss_score": 0.00182,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-47746",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-47746.json",
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. NVD: Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-47746.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. NVD: Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47746/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48115/",
      "current_public_safe_latest": true,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16236,
      "epss_score": 0.00249,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-48115",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-48115.json",
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. NVD: This vulnerability occurs whether or not federation is enabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-48115.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. NVD: This vulnerability occurs whether or not federation is enabled.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48115/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67616/",
      "current_public_safe_latest": true,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16753,
      "epss_score": 0.00253,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67616",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67616.json",
      "product": null,
      "public_safe_summary": "NVD: Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. NVD: Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue. OSV: Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67616.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. NVD: Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue. OSV: Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67616/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67617/",
      "current_public_safe_latest": true,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05676,
      "epss_score": 0.00161,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67617",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67617.json",
      "product": null,
      "public_safe_summary": "NVD: Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET... NVD: Attackers can store malicious scripts that execute without user interaction for every visitor to the public blog page and within the admin post editor, enabling session riding through same-origin fetch requests using the CSRF token embedded in the page. OSV: Microweber CMS 2.0.20 Stored XSS via tag_names Parameter",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67617.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary · user interaction required. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary · user interaction required.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET... NVD: Attackers can store malicious scripts that execute without user interaction for every visitor to the public blog page and within the admin post editor, enabling session riding through same-origin fetch requests using the CSRF token embedded in the page. OSV: Microweber CMS 2.0.20 Stored XSS via tag_names Parameter",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67617/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67969/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12682,
      "epss_score": 0.00221,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67969",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67969.json",
      "product": null,
      "public_safe_summary": "NVD: An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67969.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67969/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67970/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14077,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67970",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67970.json",
      "product": null,
      "public_safe_summary": "NVD: Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67970.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67970/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67973/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20024,
      "epss_score": 0.00278,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67973",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67973.json",
      "product": null,
      "public_safe_summary": "NVD: An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67973.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67973/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67974/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22335,
      "epss_score": 0.00301,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67974",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67974.json",
      "product": null,
      "public_safe_summary": "NVD: A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67974.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67974/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67975/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11247,
      "epss_score": 0.0021,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67975",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67975.json",
      "product": null,
      "public_safe_summary": "NVD: Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67975.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67975/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67977/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20017,
      "epss_score": 0.00278,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67977",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67977.json",
      "product": null,
      "public_safe_summary": "NVD: An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67977.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67977/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69247/",
      "current_public_safe_latest": true,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07204,
      "epss_score": 0.00175,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-69247",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-69247.json",
      "product": null,
      "public_safe_summary": "NVD: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. NVD: The same distinction was also observable by timing.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-69247.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 50.0.0..",
      "source_published_summary": "NVD: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. NVD: The same distinction was also observable by timing.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69247/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69248/",
      "current_public_safe_latest": true,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08254,
      "epss_score": 0.00185,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-69248",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-69248.json",
      "product": null,
      "public_safe_summary": "NVD: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. NVD: The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-69248.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 49.0.0..",
      "source_published_summary": "NVD: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. NVD: The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69248/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69249/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09067,
      "epss_score": 0.00192,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-69249",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-69249.json",
      "product": null,
      "public_safe_summary": "NVD: python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. NVD: Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-69249.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 49.0.0..",
      "source_published_summary": "NVD: python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. NVD: Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69249/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18667/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32019,
      "epss_score": 0.00392,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-18667",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18667.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-18667.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18667/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18684/",
      "current_public_safe_latest": true,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.7918,
      "epss_score": 0.02028,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-18684",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18684.json",
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. NVD: This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. NVD: This manipulation causes command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-18684.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. NVD: This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. NVD: This manipulation causes command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18684/timeline.json",
      "vendor": null
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20260810T220919Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}