{
  "generated_at": "2026-08-12T10:39:32.977657+00:00",
  "item_count": 20,
  "items": [
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71237/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71237.json",
      "epss": {
        "percentile": 0.34766,
        "score": 0.0042
      },
      "id": "CVE-2026-71237",
      "kev": false,
      "priority": {
        "label": "Priority review candidate",
        "reasons": [
          "CVSS CRITICAL",
          "advisory available",
          "affected product present"
        ],
        "score": 98.34766
      },
      "rank": 1,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71237.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 9.8,
        "cvss_severity": "CRITICAL",
        "defensive_priority": "Priority review candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\")."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71231/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71231.json",
      "epss": {
        "percentile": 0.28595,
        "score": 0.00358
      },
      "id": "CVE-2026-71231",
      "kev": false,
      "priority": {
        "label": "Priority review candidate",
        "reasons": [
          "CVSS CRITICAL",
          "advisory available",
          "affected product present"
        ],
        "score": 98.28595
      },
      "rank": 2,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71231.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 9.8,
        "cvss_severity": "CRITICAL",
        "defensive_priority": "Priority review candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding..."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66747/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66747.json",
      "epss": {
        "percentile": 0.44552,
        "score": 0.00579
      },
      "id": "CVE-2026-66747",
      "kev": false,
      "priority": {
        "label": "Priority review candidate",
        "reasons": [
          "CVSS CRITICAL",
          "advisory available",
          "affected product present"
        ],
        "score": 93.44552
      },
      "rank": 3,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-66747.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 9.3,
        "cvss_severity": "CRITICAL",
        "defensive_priority": "Priority review candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71238/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71238.json",
      "epss": {
        "percentile": 0.23765,
        "score": 0.00313
      },
      "id": "CVE-2026-71238",
      "kev": false,
      "priority": {
        "label": "Priority review candidate",
        "reasons": [
          "CVSS CRITICAL",
          "advisory available",
          "affected product present"
        ],
        "score": 91.23765
      },
      "rank": 4,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71238.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 9.1,
        "cvss_severity": "CRITICAL",
        "defensive_priority": "Priority review candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens..."
    },
    {
      "affected": {
        "label": "eclipse / theia",
        "product": "theia",
        "products": [
          {
            "canonicalProduct": "theia",
            "canonicalVendor": "eclipse",
            "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "theia",
            "purl": null,
            "vendor": "eclipse",
            "version": null
          }
        ],
        "vendor": "eclipse"
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60009/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-60009.json",
      "epss": {
        "percentile": 0.24854,
        "score": 0.00323
      },
      "id": "CVE-2026-60009",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 88.24854
      },
      "rank": 5,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-60009.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 8.8,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "OSV",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71235/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71235.json",
      "epss": {
        "percentile": 0.21126,
        "score": 0.00288
      },
      "id": "CVE-2026-71235",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 88.21126
      },
      "rank": 6,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71235.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 8.8,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal)."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71243/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71243.json",
      "epss": {
        "percentile": 0.21081,
        "score": 0.00288
      },
      "id": "CVE-2026-71243",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 88.21081
      },
      "rank": 7,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71243.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 8.8,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "OSV",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values"
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71233/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71233.json",
      "epss": {
        "percentile": 0.0994,
        "score": 0.00199
      },
      "id": "CVE-2026-71233",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 87.0994
      },
      "rank": 8,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71233.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 8.7,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71236/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71236.json",
      "epss": {
        "percentile": 0.0994,
        "score": 0.00199
      },
      "id": "CVE-2026-71236",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 87.0994
      },
      "rank": 9,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71236.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 8.7,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and..."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71242/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71242.json",
      "epss": {
        "percentile": 0.12013,
        "score": 0.00215
      },
      "id": "CVE-2026-71242",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 83.12013
      },
      "rank": 10,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71242.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 8.3,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "OSV",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy"
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71239/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71239.json",
      "epss": {
        "percentile": 0.13231,
        "score": 0.00225
      },
      "id": "CVE-2026-71239",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 81.13231
      },
      "rank": 11,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71239.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 8.1,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content..."
    },
    {
      "affected": {
        "label": "eclipse / theia",
        "product": "theia",
        "products": [
          {
            "canonicalProduct": "theia",
            "canonicalVendor": "eclipse",
            "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "theia",
            "purl": null,
            "vendor": "eclipse",
            "version": null
          }
        ],
        "vendor": "eclipse"
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12609/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-12609.json",
      "epss": {
        "percentile": 0.3374,
        "score": 0.00409
      },
      "id": "CVE-2026-12609",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 75.3374
      },
      "rank": 12,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-12609.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 7.5,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "OSV",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71241/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71241.json",
      "epss": {
        "percentile": 0.20477,
        "score": 0.00282
      },
      "id": "CVE-2026-71241",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 75.20477
      },
      "rank": 13,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71241.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 7.5,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71234/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71234.json",
      "epss": {
        "percentile": 0.15873,
        "score": 0.00245
      },
      "id": "CVE-2026-71234",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 75.15873
      },
      "rank": 14,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71234.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 7.5,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)..."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71232/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71232.json",
      "epss": {
        "percentile": 0.22368,
        "score": 0.003
      },
      "id": "CVE-2026-71232",
      "kev": false,
      "priority": {
        "label": "Continuous monitoring candidate",
        "reasons": [
          "CVSS HIGH",
          "advisory available",
          "affected product present"
        ],
        "score": 72.22368
      },
      "rank": 15,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71232.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 7.2,
        "cvss_severity": "HIGH",
        "defensive_priority": "Continuous monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "OSV",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function..."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71244/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71244.json",
      "epss": {
        "percentile": 0.10156,
        "score": 0.00201
      },
      "id": "CVE-2026-71244",
      "kev": false,
      "priority": {
        "label": "Routine monitoring candidate",
        "reasons": [
          "advisory available",
          "affected product present"
        ],
        "score": 65.10156
      },
      "rank": 16,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71244.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 6.5,
        "cvss_severity": "MEDIUM",
        "defensive_priority": "Routine monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a..."
    },
    {
      "affected": {
        "label": "eclipse / theia",
        "product": "theia",
        "products": [
          {
            "canonicalProduct": "theia",
            "canonicalVendor": "eclipse",
            "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "theia",
            "purl": null,
            "vendor": "eclipse",
            "version": null
          }
        ],
        "vendor": "eclipse"
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14574/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14574.json",
      "epss": {
        "percentile": 0.20449,
        "score": 0.00282
      },
      "id": "CVE-2026-14574",
      "kev": false,
      "priority": {
        "label": "Routine monitoring candidate",
        "reasons": [
          "advisory available",
          "affected product present"
        ],
        "score": 57.20449
      },
      "rank": 17,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14574.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 5.7,
        "cvss_severity": "MEDIUM",
        "defensive_priority": "Routine monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "OSV",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype)."
    },
    {
      "affected": {
        "label": "eclipse / accessibility_tools_framework",
        "product": "accessibility_tools_framework",
        "products": [
          {
            "canonicalProduct": "accessibility_tools_framework",
            "canonicalVendor": "eclipse",
            "cpe": "cpe:2.3:a:eclipse:accessibility_tools_framework:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "accessibility_tools_framework",
            "purl": null,
            "vendor": "eclipse",
            "version": null
          },
          {
            "canonicalProduct": "michecker",
            "canonicalVendor": "soumu",
            "cpe": "cpe:2.3:a:soumu:michecker:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "michecker",
            "purl": null,
            "vendor": "soumu",
            "version": null
          }
        ],
        "vendor": "eclipse"
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14304/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14304.json",
      "epss": {
        "percentile": 0.06863,
        "score": 0.00172
      },
      "id": "CVE-2026-14304",
      "kev": false,
      "priority": {
        "label": "Routine monitoring candidate",
        "reasons": [
          "advisory available",
          "affected product present"
        ],
        "score": 46.06863
      },
      "rank": 18,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-14304.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 4.6,
        "cvss_severity": "MEDIUM",
        "defensive_priority": "Routine monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "OSV",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71240/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71240.json",
      "epss": {
        "percentile": 0.08769,
        "score": 0.00189
      },
      "id": "CVE-2026-71240",
      "kev": false,
      "priority": {
        "label": "Routine monitoring candidate",
        "reasons": [
          "advisory available",
          "affected product present"
        ],
        "score": 43.08769
      },
      "rank": 19,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-71240.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 4.3,
        "cvss_severity": "MEDIUM",
        "defensive_priority": "Routine monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely..."
    },
    {
      "affected": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17578/",
      "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-17578.json",
      "epss": {
        "percentile": 0.04712,
        "score": 0.0015
      },
      "id": "CVE-2026-17578",
      "kev": false,
      "priority": {
        "label": "Routine monitoring candidate",
        "reasons": [
          "advisory available",
          "affected product present"
        ],
        "score": 23.04712
      },
      "rank": 20,
      "remediation_handoff": {
        "auto_remediation_allowed": false,
        "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578-codex-prompt.md",
        "external_execution_allowed": false,
        "human_approval_required": true,
        "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.json",
        "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2026-17578.md",
        "scan_allowed": false
      },
      "safety": {
        "auto_remediation_allowed": false,
        "external_execution_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only_static_data": true,
        "scan_allowed": false,
        "search_console_registered": true
      },
      "severity": {
        "cvss_score": 2.3,
        "cvss_severity": "LOW",
        "defensive_priority": "Routine monitoring candidate"
      },
      "sources": [
        {
          "name": "NVD",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        },
        {
          "name": "Vendor Advisory",
          "public_allowed": true,
          "retrieved_at": null,
          "url": null
        }
      ],
      "summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages."
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "read_only_static_data": true,
  "safety": {
    "auto_remediation_allowed": false,
    "external_execution_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only_static_data": true,
    "scan_allowed": false,
    "search_console_registered": true
  },
  "schema_version": "v1",
  "sort": "priority_score_desc"
}