{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-08-11T10:25:39.592098+00:00",
  "immutable_run": true,
  "item_count": 20,
  "items": [
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14175/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32286,
      "epss_score": 0.00395,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14175",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14175.json",
      "product": null,
      "public_safe_summary": "NVD: Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14175.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14175/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14192/",
      "current_public_safe_latest": true,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07117,
      "epss_score": 0.00175,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14192",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14192.json",
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Stored XSS. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14192.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Stored XSS. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14192/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14194/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21801,
      "epss_score": 0.00295,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14194",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14194.json",
      "product": null,
      "public_safe_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Path Traversal. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14194.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Path Traversal. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14194/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14202/",
      "current_public_safe_latest": true,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09691,
      "epss_score": 0.00197,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14202",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14202.json",
      "product": null,
      "public_safe_summary": "NVD: Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Account Footprinting. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14202.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Account Footprinting. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14202/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14219/",
      "current_public_safe_latest": true,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05658,
      "epss_score": 0.0016,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14219",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14219.json",
      "product": null,
      "public_safe_summary": "NVD: URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Phishing. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14219.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Phishing. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14219/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14465/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1894,
      "epss_score": 0.0027,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14465",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14465.json",
      "product": null,
      "public_safe_summary": "NVD: Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14465.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14465/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14804/",
      "current_public_safe_latest": true,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.22831,
      "epss_score": 0.00305,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14804",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14804.json",
      "product": null,
      "public_safe_summary": "NVD: Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14804.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14804/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14838/",
      "current_public_safe_latest": true,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17279,
      "epss_score": 0.00257,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14838",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14838.json",
      "product": null,
      "public_safe_summary": "NVD: Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Session Hijacking. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14838.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Session Hijacking. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14838/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15721/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.13986,
      "epss_score": 0.00231,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-15721",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15721.json",
      "product": null,
      "public_safe_summary": "NVD: Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows SQL Injection. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-15721.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows SQL Injection. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15721/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18772/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03141,
      "epss_score": 0.00132,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-18772",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18772.json",
      "product": null,
      "public_safe_summary": "NVD: Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-18772.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18772/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / jetty",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10050/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38242,
      "epss_score": 0.0047,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-10050",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-10050.json",
      "product": "jetty",
      "public_safe_summary": "NVD: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. NVD: This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. NVD: If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by ?.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-10050.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / jetty",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. NVD: This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. NVD: If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by ?.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10050/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66883/",
      "current_public_safe_latest": true,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21251,
      "epss_score": 0.0029,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-66883",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66883.json",
      "product": null,
      "public_safe_summary": "NVD: Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session. NVD: This vulnerability is associated with program files lib/oidcc/plug/authorize.ex and lib/oidcc/plug/authorization_callback.ex, and program routines Oidcc.Plug.Authorize.call/2 and Oidcc.Plug.AuthorizationCallback.call/2. NVD: Oidcc.Plug.Authorize.call/2 reads the initiating client's user agent with get_req_header(conn, \"User-Agent\").",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-66883.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session. NVD: This vulnerability is associated with program files lib/oidcc/plug/authorize.ex and lib/oidcc/plug/authorization_callback.ex, and program routines Oidcc.Plug.Authorize.call/2 and Oidcc.Plug.AuthorizationCallback.call/2. NVD: Oidcc.Plug.Authorize.call/2 reads the initiating client's user agent with get_req_header(conn, \"User-Agent\").",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66883/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66884/",
      "current_public_safe_latest": true,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11749,
      "epss_score": 0.00214,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-66884",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66884.json",
      "product": null,
      "public_safe_summary": "NVD: Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated. NVD: This vulnerability is associated with program file lib/oidcc/plug/authorization_callback.ex and program routine Oidcc.Plug.AuthorizationCallback.call/2. NVD: A callback request that carries no Oidcc.Plug.Authorize session is processed with every security check disabled rather than being rejected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-66884.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated. NVD: This vulnerability is associated with program file lib/oidcc/plug/authorization_callback.ex and program routine Oidcc.Plug.AuthorizationCallback.call/2. NVD: A callback request that carries no Oidcc.Plug.Authorize session is processed with every security check disabled rather than being rejected.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66884/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10709/",
      "current_public_safe_latest": true,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04284,
      "epss_score": 0.00145,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-10709",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-10709.json",
      "product": null,
      "public_safe_summary": "NVD: A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. NVD: A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-10709.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. NVD: A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10709/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10710/",
      "current_public_safe_latest": true,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04285,
      "epss_score": 0.00145,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-10710",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-10710.json",
      "product": null,
      "public_safe_summary": "NVD: A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. NVD: A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-10710.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. NVD: A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10710/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18806/",
      "current_public_safe_latest": true,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01045,
      "epss_score": 0.00101,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-18806",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18806.json",
      "product": null,
      "public_safe_summary": "NVD: External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. NVD: This issue affects pardus-image-writer: before 0.9.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-18806.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. NVD: This issue affects pardus-image-writer: before 0.9.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18806/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18809/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11351,
      "epss_score": 0.00211,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-18809",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18809.json",
      "product": null,
      "public_safe_summary": "NVD: Information disclosure in Firefox for Android and Firefox Focus for Android. NVD: This vulnerability was fixed in Firefox 153.0.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-18809.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: Information disclosure in Firefox for Android and Firefox Focus for Android. NVD: This vulnerability was fixed in Firefox 153.0.3.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18809/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / milo",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58080/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18869,
      "epss_score": 0.00269,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-58080",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-58080.json",
      "product": "milo",
      "public_safe_summary": "NVD: In Eclipse Milo versions 1.0.0 through 1.1.4, OpcUaServerConfig.copy() fails to preserve a configured RoleMapper. NVD: On servers that rely on role permissions and construct the running configuration through copy(), sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted... OSV: In Eclipse Milo versions 1.0.0 through 1.1.4, OpcUaServerConfig.copy() fails to preserve a configured RoleMapper.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-58080.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / milo",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Milo versions 1.0.0 through 1.1.4, OpcUaServerConfig.copy() fails to preserve a configured RoleMapper. NVD: On servers that rely on role permissions and construct the running configuration through copy(), sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted... OSV: In Eclipse Milo versions 1.0.0 through 1.1.4, OpcUaServerConfig.copy() fails to preserve a configured RoleMapper.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58080/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "eclipse / milo",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60007/",
      "current_public_safe_latest": true,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.31124,
      "epss_score": 0.00383,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-60007",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-60007.json",
      "product": "milo",
      "public_safe_summary": "NVD: In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username... OSV: In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-60007.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / milo",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username... OSV: In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60007/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "eclipse / milo",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61387/",
      "current_public_safe_latest": true,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27156,
      "epss_score": 0.00345,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-61387",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-61387.json",
      "product": "milo",
      "public_safe_summary": "NVD: In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. NVD: Deeply nested PubSub ExtensionObjects in a CreateMonitoredItems event filter can trigger a StackOverflowError during decoding, allowing an unauthenticated remote client to exhaust a finite global monitored-item quota and prevent all clients from creating new... NVD: Existing monitored items and other server functions remain unaffected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-61387.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / milo",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. NVD: Deeply nested PubSub ExtensionObjects in a CreateMonitoredItems event filter can trigger a StackOverflowError during decoding, allowing an unauthenticated remote client to exhaust a finite global monitored-item quota and prevent all clients from creating new... NVD: Existing monitored items and other server functions remain unaffected.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61387/timeline.json",
      "vendor": "eclipse"
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20260811T102539Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}