{
  "query": {
    "page": "11"
  },
  "count": 20,
  "total": 46382,
  "page": 11,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T06:45:27.610Z",
    "kev": "2026-10-06T07:44:30.071Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T07:45:30.209Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=11",
    "next": "https://spydr.io/threats.json?page=12"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-105637",
      "url": "https://spydr.io/cve/CVE-2026-105637",
      "published": "2026-10-05T19:17:17.860Z",
      "modified": "2026-10-05T20:17:11.203Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, draft_issue_id, or project_id to an entity the attacker controls. Plane then treats the attacker's project as the new owner and provides a presigned download URL for the hijacked file. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-105636",
      "url": "https://spydr.io/cve/CVE-2026-105636",
      "published": "2026-10-05T19:17:17.693Z",
      "modified": "2026-10-05T19:17:17.827Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-105635",
      "url": "https://spydr.io/cve/CVE-2026-105635",
      "published": "2026-10-05T19:17:17.503Z",
      "modified": "2026-10-05T19:17:17.650Z",
      "score": 7.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-200",
        "CWE-284",
        "CWE-862"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-105634",
      "url": "https://spydr.io/cve/CVE-2026-105634",
      "published": "2026-10-05T19:17:17.330Z",
      "modified": "2026-10-05T19:17:17.467Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0."
    },
    {
      "id": "CVE-2026-105387",
      "url": "https://spydr.io/cve/CVE-2026-105387",
      "published": "2026-10-05T19:17:16.910Z",
      "modified": "2026-10-05T19:17:16.910Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "girishsaraf"
      ],
      "products": [
        "girishsaraf Online-Appointment-Booking-System"
      ],
      "cwes": [
        "CWE-74",
        "CWE-89"
      ],
      "description": "A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105386",
      "url": "https://spydr.io/cve/CVE-2026-105386",
      "published": "2026-10-05T19:17:16.700Z",
      "modified": "2026-10-05T19:17:16.700Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "onetwothreeneth"
      ],
      "products": [
        "onetwothreeneth HospitalManagementSystem"
      ],
      "cwes": [
        "CWE-74",
        "CWE-89"
      ],
      "description": "A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105326",
      "url": "https://spydr.io/cve/CVE-2026-105326",
      "published": "2026-10-05T19:17:16.393Z",
      "modified": "2026-10-05T19:17:16.393Z",
      "score": 2.5,
      "severity": "low",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "redhat.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Red Hat"
      ],
      "products": [
        "Red Hat Enterprise Linux 10",
        "Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 9",
        "Red Hat Hardened Images"
      ],
      "cwes": [
        "CWE-88"
      ],
      "description": "An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with \"-\" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user."
    },
    {
      "id": "CVE-2026-104714",
      "url": "https://spydr.io/cve/CVE-2026-104714",
      "published": "2026-10-05T19:17:14.883Z",
      "modified": "2026-10-05T20:17:09.237Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Struts"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation, so a value belonging to one user can appear in another user's response, or the rendering can fail and surface as a server error. Applications whose localized messages format no date or time arguments are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
    },
    {
      "id": "CVE-2026-104713",
      "url": "https://spydr.io/cve/CVE-2026-104713",
      "published": "2026-10-05T19:17:14.757Z",
      "modified": "2026-10-05T20:17:09.103Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Struts"
      ],
      "cwes": [
        "CWE-770"
      ],
      "description": "Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to other users. No additional setting has to be enabled. Applications that do not use the REST plugin are not affected. This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
    },
    {
      "id": "CVE-2026-104712",
      "url": "https://spydr.io/cve/CVE-2026-104712",
      "published": "2026-10-05T19:17:14.630Z",
      "modified": "2026-10-05T20:17:08.940Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Struts"
      ],
      "cwes": [
        "CWE-405"
      ],
      "description": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected. This issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
    },
    {
      "id": "CVE-2026-104711",
      "url": "https://spydr.io/cve/CVE-2026-104711",
      "published": "2026-10-05T19:17:14.497Z",
      "modified": "2026-10-05T20:17:08.790Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Struts"
      ],
      "cwes": [
        "CWE-917"
      ],
      "description": "Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default. Applications using the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
    },
    {
      "id": "CVE-2026-103352",
      "url": "https://spydr.io/cve/CVE-2026-103352",
      "published": "2026-10-05T19:17:13.847Z",
      "modified": "2026-10-05T19:17:13.847Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WP BASE"
      ],
      "products": [
        "WP BASE Booking"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0."
    },
    {
      "id": "CVE-2026-103349",
      "url": "https://spydr.io/cve/CVE-2026-103349",
      "published": "2026-10-05T19:17:13.703Z",
      "modified": "2026-10-05T19:17:13.703Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Rymera Web Co"
      ],
      "products": [
        "Rymera Web Co Product Feed PRO for WooCommerce"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7."
    },
    {
      "id": "CVE-2026-103334",
      "url": "https://spydr.io/cve/CVE-2026-103334",
      "published": "2026-10-05T19:17:13.543Z",
      "modified": "2026-10-05T19:17:13.543Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Etoile Web Design Incorporated"
      ],
      "products": [
        "Etoile Web Design Incorporated Five Star Restaurant Reservations"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24."
    },
    {
      "id": "CVE-2026-103086",
      "url": "https://spydr.io/cve/CVE-2026-103086",
      "published": "2026-10-05T19:17:13.403Z",
      "modified": "2026-10-05T19:17:13.403Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Stiofan"
      ],
      "products": [
        "Stiofan UsersWP"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74."
    },
    {
      "id": "CVE-2026-103085",
      "url": "https://spydr.io/cve/CVE-2026-103085",
      "published": "2026-10-05T19:17:13.240Z",
      "modified": "2026-10-05T19:17:13.240Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WP User Manager"
      ],
      "products": [
        "WP User Manager"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20."
    },
    {
      "id": "CVE-2026-102383",
      "url": "https://spydr.io/cve/CVE-2026-102383",
      "published": "2026-10-05T19:17:12.457Z",
      "modified": "2026-10-05T19:17:12.457Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "VillaTheme"
      ],
      "products": [
        "VillaTheme Lookzy"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in VillaTheme Lookzy woo-lookbook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lookzy: from n/a through 1.1.14."
    },
    {
      "id": "CVE-2026-100515",
      "url": "https://spydr.io/cve/CVE-2026-100515",
      "published": "2026-10-05T19:17:12.200Z",
      "modified": "2026-10-05T19:17:12.200Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "VillaTheme"
      ],
      "products": [
        "VillaTheme Photo Reviews for WooCommerce"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30."
    },
    {
      "id": "CVE-2026-100509",
      "url": "https://spydr.io/cve/CVE-2026-100509",
      "published": "2026-10-05T19:17:12.047Z",
      "modified": "2026-10-05T19:17:12.047Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Webful Creations"
      ],
      "products": [
        "Webful Creations RepairBuddy"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Stored XSS.This issue affects RepairBuddy: from n/a through 4.1225."
    },
    {
      "id": "CVE-2026-93323",
      "url": "https://spydr.io/cve/CVE-2026-93323",
      "published": "2026-10-05T18:17:39.630Z",
      "modified": "2026-10-05T19:17:26.403Z",
      "score": 6.8,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "moby"
      ],
      "products": [
        "moby BuildKit"
      ],
      "cwes": [
        "CWE-789"
      ],
      "description": "The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
