← All credits
Ziyue
3 vulnerability records and advisories credit this contributor.
CVE-2026-94269
Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch
CVE-2026-94250
Apache APISIX: Batch response aggregation can exhaust worker memory
CVE-2026-10055
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full respons