← All credits
waydeshi
3 vulnerability records and advisories credit this contributor.
CVE-2026-68497
jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of service
CVE-2026-19032
jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path
CVE-2026-82417
qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property