{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-09-26T13:48:45.361258+00:00",
  "immutable_run": true,
  "item_count": 19,
  "items": [
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93999/",
      "current_public_safe_latest": true,
      "cvss_score": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12055,
      "epss_score": 0.00227,
      "first_observed_at": "2026-09-26T08:39:24.685133+00:00",
      "id": "CVE-2026-93999",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93999.json",
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. NVD: The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. NVD: Keycloak fails to verify if the target audience client is still enabled before issuing a new access token.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93999.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. NVD: The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. NVD: Keycloak fails to verify if the target audience client is still enabled before issuing a new access token.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93999/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-94000/",
      "current_public_safe_latest": true,
      "cvss_score": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.31664,
      "epss_score": 0.00401,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-94000",
      "impact_tags": [
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-94000.json",
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. NVD: The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. NVD: This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-94000.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. NVD: The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. NVD: This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-94000/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-94001/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.35919,
      "epss_score": 0.00443,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-94001",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-94001.json",
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. NVD: The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. NVD: This allows a delegated administrator, who should be restricted from resetting passwords, to delete a user's password credentials, resulting in the user being unable to log in.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-94001.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. NVD: The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. NVD: This allows a delegated administrator, who should be restricted from resetting passwords, to delete a user's password credentials, resulting in the user being unable to log in.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-94001/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-82560/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.47982,
      "epss_score": 0.0063,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-82560",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-82560.json",
      "product": null,
      "public_safe_summary": "NVD: Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. NVD: Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. NVD: When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-82560.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. NVD: Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. NVD: When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-82560/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-82672/",
      "current_public_safe_latest": true,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.41999,
      "epss_score": 0.00524,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-82672",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-82672.json",
      "product": null,
      "public_safe_summary": "NVD: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue... NVD: Mint.HTTP1.Parse.chunk_size/1 in lib/mint/http1/parse.ex stops at the first non-hexadecimal byte of a chunked response's chunk-size line and returns the remainder unexamined. NVD: Mint.HTTP1.decode_body/5 in lib/mint/http1.ex then discards every byte up to the CRLF with Parse.ignore_until_crlf/1, so the accepted grammar is a run of hex digits followed by arbitrary bytes, where RFC 9112 permits only a ;-introduced chunk extension.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-82672.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue... NVD: Mint.HTTP1.Parse.chunk_size/1 in lib/mint/http1/parse.ex stops at the first non-hexadecimal byte of a chunked response's chunk-size line and returns the remainder unexamined. NVD: Mint.HTTP1.decode_body/5 in lib/mint/http1.ex then discards every byte up to the CRLF with Parse.ignore_until_crlf/1, so the accepted grammar is a run of hex digits followed by arbitrary bytes, where RFC 9112 permits only a ;-introduced chunk extension.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-82672/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93954/",
      "current_public_safe_latest": true,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.30918,
      "epss_score": 0.00394,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-93954",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93954.json",
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. NVD: Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. NVD: Such manipulation leads to incorrect authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93954.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. NVD: Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. NVD: Such manipulation leads to incorrect authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93954/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93955/",
      "current_public_safe_latest": true,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.3299,
      "epss_score": 0.00414,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-93955",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93955.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. NVD: Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. NVD: Performing a manipulation of the argument bookId results in authorization bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93955.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. NVD: Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. NVD: Performing a manipulation of the argument bookId results in authorization bypass.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93955/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93956/",
      "current_public_safe_latest": true,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.33264,
      "epss_score": 0.00416,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-93956",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93956.json",
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. NVD: Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. NVD: Executing a manipulation of the argument Query can lead to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93956.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: of.",
      "source_published_summary": "NVD: A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. NVD: Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. NVD: Executing a manipulation of the argument Query can lead to cross site scripting.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93956/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93988/",
      "current_public_safe_latest": true,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.43744,
      "epss_score": 0.00551,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-93988",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93988.json",
      "product": null,
      "public_safe_summary": "NVD: QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. NVD: Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data. OSV: QloApps through 1.7.0 Arbitrary File Read via getEmailHTML",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93988.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. NVD: Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data. OSV: QloApps through 1.7.0 Arbitrary File Read via getEmailHTML",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93988/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93989/",
      "current_public_safe_latest": true,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.22421,
      "epss_score": 0.00321,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-93989",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93989.json",
      "product": null,
      "public_safe_summary": "NVD: vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). NVD: Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens. OSV: vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93989.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). NVD: Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens. OSV: vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93989/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93990/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27801,
      "epss_score": 0.00366,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-93990",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93990.json",
      "product": null,
      "public_safe_summary": "NVD: Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. NVD: Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks. OSV: Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93990.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. NVD: Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks. OSV: Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93990/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93991/",
      "current_public_safe_latest": true,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35254,
      "epss_score": 0.00436,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-93991",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93991.json",
      "product": null,
      "public_safe_summary": "NVD: Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. NVD: Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations. OSV: Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Selector",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93991.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. NVD: Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations. OSV: Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Selector",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93991/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93992/",
      "current_public_safe_latest": true,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.58133,
      "epss_score": 0.00905,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-93992",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93992.json",
      "product": null,
      "public_safe_summary": "NVD: Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. NVD: Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled. OSV: Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93992.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. NVD: Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled. OSV: Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93992/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-93993/",
      "current_public_safe_latest": true,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.57218,
      "epss_score": 0.00874,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-93993",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-93993.json",
      "product": null,
      "public_safe_summary": "NVD: Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. NVD: Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe. OSV: Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-93993.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. NVD: Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe. OSV: Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-93993/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "exim / exim",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-94054/",
      "current_public_safe_latest": true,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16895,
      "epss_score": 0.00268,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-94054",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-94054.json",
      "product": "exim",
      "public_safe_summary": "NVD: Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-94054.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: exim / exim",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-94054/timeline.json",
      "vendor": "exim"
    },
    {
      "affected_label": "exim / exim",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-94055/",
      "current_public_safe_latest": true,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.18867,
      "epss_score": 0.00286,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-94055",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-94055.json",
      "product": "exim",
      "public_safe_summary": "NVD: Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-94055.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: exim / exim",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-94055/timeline.json",
      "vendor": "exim"
    },
    {
      "affected_label": "exim / exim",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-94056/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26568,
      "epss_score": 0.00355,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-94056",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-94056.json",
      "product": "exim",
      "public_safe_summary": "NVD: Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-94056.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: exim / exim",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-94056/timeline.json",
      "vendor": "exim"
    },
    {
      "affected_label": "exim / exim",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-94057/",
      "current_public_safe_latest": true,
      "cvss_score": 4.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0837,
      "epss_score": 0.00197,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-94057",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-94057.json",
      "product": "exim",
      "public_safe_summary": "NVD: Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-94057.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: exim / exim",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-94057/timeline.json",
      "vendor": "exim"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-86551/",
      "current_public_safe_latest": true,
      "cvss_score": 3.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.08138,
      "epss_score": 0.00195,
      "first_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "id": "CVE-2026-86551",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-09-26T13:48:19.354151+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-86551.json",
      "product": null,
      "public_safe_summary": "NVD: The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/items/CVE-2026-86551.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-86551/timeline.json",
      "vendor": null
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20260926T134845Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260926T134845Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}