{
 "npmjs.org": {
  "uri-js": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-333w-rxj3-f55r"
   ],
   "sample_summary": "Regular Expression Denial Of Service in uri-js"
  },
  "eslint-utils": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-3gx7-xhv7-5mx3"
   ],
   "sample_summary": "Arbitrary Code Execution in eslint-utils"
  },
  "set-value": {
   "n_advisories": 5,
   "n_malicious": 0,
   "n_real_cve": 5,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-4g88-fppr-53pp",
    "GHSA-4g88-fppr-53pp",
    "GHSA-4jqc-8m5r-9rpr",
    "GHSA-4jqc-8m5r-9rpr"
   ],
   "sample_summary": "Prototype Pollution in set-value"
  },
  "fsevents": {
   "n_advisories": 2,
   "n_malicious": 1,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-8r6j-v8pm-fqw3",
    "MAL-2023-462"
   ],
   "sample_summary": "Code injection in fsevents"
  },
  "sockjs": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-c9g6-9335-x697",
    "GHSA-hh8v-jmh3-9437"
   ],
   "sample_summary": "Improper Input Validation in SocksJS-Node"
  },
  "rc": {
   "n_advisories": 3,
   "n_malicious": 0,
   "n_real_cve": 3,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-g2q5-5433-rhrf",
    "GHSA-g2q5-5433-rhrf",
    "GHSA-g2q5-5433-rhrf"
   ],
   "sample_summary": "Embedded malware in rc"
  },
  "websocket-extensions": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-g78m-2chm-r7qv"
   ],
   "sample_summary": "Regular Expression Denial of Service in websocket-extensions (NPM package)"
  },
  "deep-extend": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-hr2v-3952-633q"
   ],
   "sample_summary": "Prototype Pollution in deep-extend"
  },
  "querystringify": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-hxcm-v35h-mg2x"
   ],
   "sample_summary": "Prototype Pollution in querystringify"
  },
  "websocket-driver": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-mp7j-qc5w-4988",
    "GHSA-xv26-6w52-cph6"
   ],
   "sample_summary": "websocket-driver: Resource limit bypass via message compression"
  }
 },
 "proxy.golang.org": {
  "github.com/masterminds/goutils": {
   "n_advisories": 3,
   "n_malicious": 0,
   "n_real_cve": 3,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-3839-6r69-m497",
    "GHSA-xg2h-wx96-xgxr",
    "GO-2022-0411"
   ],
   "sample_summary": "Duplicate Advisory: GoUtils's randomly-generated alphanumeric strings contain significantl"
  },
  "gopkg.in/src-d/go-git.v4": {
   "n_advisories": 8,
   "n_malicious": 0,
   "n_real_cve": 8,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-449p-3h89-pw88",
    "GHSA-mw99-9chc-xw7r",
    "GHSA-r9px-m959-cxf4",
    "GHSA-v725-9546-7q7m"
   ],
   "sample_summary": "Maliciously crafted Git server replies can lead to path traversal and RCE on go-git client"
  },
  "github.com/cloudflare/golz4": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-4wp2-8rm2-jgmh",
    "GO-2020-0022"
   ],
   "sample_summary": "LZ4 vulnerable to Out-of-bounds Write"
  },
  "github.com/masterminds/vcs": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-6635-c626-vj4r",
    "GO-2022-0414"
   ],
   "sample_summary": "Command Injection Vulnerability with Mercurial in VCS"
  },
  "github.com/aws/aws-sdk-go": {
   "n_advisories": 7,
   "n_malicious": 0,
   "n_real_cve": 7,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-6jvc-q2x7-pchv",
    "GHSA-76wf-9vgp-pj7w",
    "GHSA-7f33-f4f5-xwgw",
    "GHSA-f5pg-7wfw-84q9"
   ],
   "sample_summary": "AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a"
  },
  "gopkg.in/yaml.v2": {
   "n_advisories": 6,
   "n_malicious": 0,
   "n_real_cve": 6,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-6q6q-88xp-6f2r",
    "GHSA-r88r-gmrh-7j83",
    "GHSA-wxc4-f4m6-wwqv",
    "GO-2020-0036"
   ],
   "sample_summary": "yaml package for Go can consume excessive amounts of CPU or memory"
  },
  "github.com/gogo/protobuf": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-c3h9-896r-86jm",
    "GO-2021-0053"
   ],
   "sample_summary": "Improper Input Validation in GoGo Protobuf"
  },
  "gopkg.in/square/go-jose.v2": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-c5q2-7r4c-mv6g",
    "GO-2024-2631"
   ],
   "sample_summary": "Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)"
  },
  "github.com/btcsuite/go-socks": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-gxgj-xjcw-fv9p",
    "GO-2020-0024"
   ],
   "sample_summary": "socks Infinite Loop vulnerability"
  },
  "github.com/dgrijalva/jwt-go": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-w73w-5m7g-f7qc",
    "GO-2020-0017"
   ],
   "sample_summary": "Authorization bypass in github.com/dgrijalva/jwt-go"
  }
 },
 "pypi.org": {
  "dash-html-components": {
   "n_advisories": 3,
   "n_malicious": 0,
   "n_real_cve": 3,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-547x-748v-vp6p",
    "GHSA-547x-748v-vp6p",
    "PYSEC-2026-220"
   ],
   "sample_summary": "Dash apps vulnerable to Cross-site Scripting"
  },
  "pycrypto": {
   "n_advisories": 8,
   "n_malicious": 0,
   "n_real_cve": 8,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-6528-wvf6-f6qg",
    "GHSA-cq27-v7xp-c356",
    "GHSA-v367-p58w-98h5",
    "GHSA-x377-f64p-hf5j"
   ],
   "sample_summary": "Pycrypto generates weak key parameters"
  },
  "pyxdg": {
   "n_advisories": 4,
   "n_malicious": 0,
   "n_real_cve": 4,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-7372-q459-jxhr",
    "GHSA-r6v3-hpxj-r8rv",
    "PYSEC-2014-95",
    "PYSEC-2019-199"
   ],
   "sample_summary": "pyxdg Arbitrary File Overwrite via Race Condition"
  },
  "typed-ast": {
   "n_advisories": 6,
   "n_malicious": 0,
   "n_real_cve": 6,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-7xxv-wpxj-mx5v",
    "GHSA-m3jw-62m7-jjcm",
    "PYSEC-2019-130",
    "PYSEC-2019-131"
   ],
   "sample_summary": "typed-ast Out-of-bounds Read"
  },
  "pdfkit": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-9g3x-6x24-vf9f",
    "PYSEC-2026-2860"
   ],
   "sample_summary": "pdfkit: Path traversal in from_string"
  },
  "codecov": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-h3qr-fjhm-jphw",
    "PYSEC-2022-238"
   ],
   "sample_summary": "Codecov does not sanitize gcov arguments"
  },
  "py": {
   "n_advisories": 5,
   "n_malicious": 0,
   "n_real_cve": 5,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-hj5v-574p-mj7c",
    "GHSA-w596-4wvx-j9j6",
    "PYSEC-2020-92",
    "PYSEC-2022-42969"
   ],
   "sample_summary": "py vulnerable to Regular Expression Denial of Service"
  },
  "python-apt": {
   "n_advisories": 10,
   "n_malicious": 0,
   "n_real_cve": 10,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-pj65-3pf6-c5q4",
    "GHSA-pj65-3pf6-c5q4",
    "GHSA-pj65-3pf6-c5q4",
    "GHSA-pj65-3pf6-c5q4"
   ],
   "sample_summary": "python-apt Does Not Check Hash Signature"
  },
  "diskcache": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-w8v5-vhqr-4h9v",
    "PYSEC-2026-2447"
   ],
   "sample_summary": "DiskCache has unsafe pickle deserialization"
  },
  "django-rest-framework": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-xqcf-hj92-967m",
    "PYSEC-2026-804"
   ],
   "sample_summary": "Django REST framework XSS Vulnerability"
  }
 },
 "repo1.maven.org": {
  "log4j:log4j": {
   "n_advisories": 6,
   "n_malicious": 0,
   "n_real_cve": 6,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-2qrg-x229-3v8q",
    "GHSA-65fg-84f6-3jq3",
    "GHSA-f7vh-qwp3-x37m",
    "GHSA-fp5r-v3w9-4333"
   ],
   "sample_summary": "Deserialization of Untrusted Data in Log4j"
  },
  "mysql:mysql-connector-java": {
   "n_advisories": 9,
   "n_malicious": 0,
   "n_real_cve": 9,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-2xxh-f8r3-hvvr",
    "GHSA-4vrv-ch96-6h42",
    "GHSA-cjcf-wm2p-59h5",
    "GHSA-g76j-4cxx-23h9"
   ],
   "sample_summary": "Improper Access Control in MySQL Connectors Java"
  },
  "commons-httpclient:commons-httpclient": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-3832-9276-x7gf"
   ],
   "sample_summary": "Improper Certificate Validation in Apache Commons HttpClient"
  },
  "org.apache.derby:derby": {
   "n_advisories": 22,
   "n_malicious": 0,
   "n_real_cve": 22,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-42xw-p62x-hwcf",
    "GHSA-fh32-35w2-rxcc",
    "GHSA-rcjc-c4pj-xxrp",
    "GHSA-rcjc-c4pj-xxrp"
   ],
   "sample_summary": "Improper Access Control in Apache Derby"
  },
  "org.apache.velocity:velocity": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-59j4-wjwp-mw9m"
   ],
   "sample_summary": "Sandbox Bypass in Apache Velocity Engine"
  },
  "commons-collections:commons-collections": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-6hgm-866r-3cjv",
    "GHSA-fjq5-5j5f-mvxh"
   ],
   "sample_summary": "Insecure Deserialization in Apache Commons Collection"
  },
  "dom4j:dom4j": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-6pcc-3rfx-4gpm",
    "GHSA-hwj3-m3p6-hj38"
   ],
   "sample_summary": "Dom4j contains a XML Injection vulnerability"
  },
  "org.codehaus.jackson:jackson-mapper-asl": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-c27h-mcmw-48hv",
    "GHSA-r6j9-8759-g62w"
   ],
   "sample_summary": "Deserialization of Untrusted Data in org.codehaus.jackson:jackson-mapper-asl"
  },
  "org.apache.commons:commons-io": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-gwrp-pvrq-jmwv"
   ],
   "sample_summary": "Path Traversal and Improper Input Validation in Apache Commons IO"
  },
  "commons-lang:commons-lang": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-j288-q9x7-2f5v"
   ],
   "sample_summary": "Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs"
  }
 },
 "nuget.org": {
  "jquery": {
   "n_advisories": 22,
   "n_malicious": 0,
   "n_real_cve": 22,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-257q-pv89-v3xv",
    "GHSA-257q-pv89-v3xv",
    "GHSA-2pqj-h3vj-pqgw",
    "GHSA-2pqj-h3vj-pqgw"
   ],
   "sample_summary": "Duplicate Advisory: jQuery Cross Site Scripting vulnerability"
  },
  "curl": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-674j-7m97-j2p9"
   ],
   "sample_summary": "curl FTP path confusion leads to NIL byte out of bounds write"
  },
  "bootstrap-select": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-7c82-mp33-r854",
    "GHSA-7c82-mp33-r854"
   ],
   "sample_summary": "Cross-site scripting in bootstrap-select"
  },
  "system.data.sqlclient": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-8g2p-5pqh-5jmc",
    "GHSA-98g6-xh36-x2p7"
   ],
   "sample_summary": ".NET Information Disclosure Vulnerability"
  },
  "telerikmvcextensions": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-8h7p-qjv8-9mp4"
   ],
   "sample_summary": "Improper Access Control in Telerik Extensions"
  },
  "bootstrap.less": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-9v3m-8fp8-mj99"
   ],
   "sample_summary": "Bootstrap Vulnerable to Cross-Site Scripting"
  },
  "starkbank-ecdsa": {
   "n_advisories": 4,
   "n_malicious": 0,
   "n_real_cve": 4,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-9wx7-jrvc-28mm",
    "GHSA-9wx7-jrvc-28mm",
    "GHSA-9wx7-jrvc-28mm",
    "GHSA-j3jw-j2j8-2wv9"
   ],
   "sample_summary": "Signature verification vulnerability in Stark Bank ecdsa libraries"
  },
  "jquery.cookie": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-gcx5-3p5f-f8vp"
   ],
   "sample_summary": "Prototype Pollution in jquery.cookie"
  }
 },
 "rubygems.org": {
  "paperclip": {
   "n_advisories": 3,
   "n_malicious": 0,
   "n_real_cve": 3,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-5jcf-c5rg-rmm8",
    "GHSA-6jvm-3j5h-79f6",
    "GHSA-phmw-pv3f-vvx7"
   ],
   "sample_summary": "paperclip Server-Side Request Forgery vulnerability"
  },
  "ruby-openid": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-6c8p-qphv-668v",
    "GHSA-fqfj-cmh6-hj49"
   ],
   "sample_summary": "Denial of service in ruby-openid"
  },
  "rdiscount": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-6r34-94wq-jhrc"
   ],
   "sample_summary": "rdiscount has an Out-of-bounds Read"
  },
  "jruby-openssl": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-72qj-48g4-5xgx",
    "GHSA-xgv7-pqqh-h2w9"
   ],
   "sample_summary": "JRuby-OpenSSL has hostname verification disabled by default"
  },
  "extlib": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-9h36-4jf2-hx53"
   ],
   "sample_summary": "extlib does not properly restrict casts of string values"
  },
  "cocaine": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-c43v-hrmg-56r4"
   ],
   "sample_summary": "Cocaine Gem OS Command Injection vulnerability"
  },
  "moped": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-f93j-hmcr-jcwh",
    "GHSA-f93j-hmcr-jcwh"
   ],
   "sample_summary": "Moped Rubygem Data Injection Vulnerability"
  },
  "websocket-extensions": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-g6wq-qcwm-j5g2"
   ],
   "sample_summary": "Regular Expression Denial of Service in websocket-extensions (RubyGem)"
  },
  "em-http-request": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-q27f-v3r6-9v77"
   ],
   "sample_summary": "Improper Certificate Validation in EM-HTTP-Request"
  },
  "rack-ssl": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-v3rr-cph9-2g2q"
   ],
   "sample_summary": "rack-ssl Cross-site Scripting vulnerability"
  }
 },
 "crates.io": {
  "failure": {
   "n_advisories": 4,
   "n_malicious": 0,
   "n_real_cve": 4,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-jq66-xh47-j9f3",
    "GHSA-r98r-j25q-rmpr",
    "RUSTSEC-2019-0036",
    "RUSTSEC-2020-0036"
   ],
   "sample_summary": "Type confusion if __private_get_type_id__ is overriden"
  },
  "untrusted": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-wq8f-46ww-6c2h",
    "RUSTSEC-2018-0001"
   ],
   "sample_summary": "Integer underflow in untrusted"
  },
  "dirs": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "RUSTSEC-2020-0053"
   ],
   "sample_summary": "dirs is unmaintained, use dirs-next instead"
  },
  "structopt": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "RUSTSEC-2022-0104"
   ],
   "sample_summary": "`structopt` is in maintenance mode"
  },
  "proc-macro-error": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "RUSTSEC-2024-0370"
   ],
   "sample_summary": "proc-macro-error is unmaintained"
  },
  "paste": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "RUSTSEC-2024-0436"
   ],
   "sample_summary": "paste - no longer maintained"
  },
  "adler": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "RUSTSEC-2025-0056"
   ],
   "sample_summary": "adler crate is unmaintained, use adler2 instead"
  },
  "fxhash": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "RUSTSEC-2025-0057"
   ],
   "sample_summary": "fxhash - no longer maintained"
  },
  "rustls-pemfile": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "RUSTSEC-2025-0134"
   ],
   "sample_summary": "rustls-pemfile is unmaintained"
  },
  "bincode": {
   "n_advisories": 1,
   "n_malicious": 0,
   "n_real_cve": 1,
   "any_with_version_range": true,
   "sample_ids": [
    "RUSTSEC-2025-0141"
   ],
   "sample_summary": "Bincode is unmaintained"
  }
 },
 "packagist.org": {
  "phpoffice/phpexcel": {
   "n_advisories": 23,
   "n_malicious": 0,
   "n_real_cve": 23,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-28rm-rj57-qjpv",
    "GHSA-3m9x-2qfj-xvq4",
    "GHSA-4mqv-gcr3-pff9",
    "GHSA-5gpr-w2p5-6m37"
   ],
   "sample_summary": "PHPExcel vulnerable to XXE attacks through libxml"
  },
  "zendframework/zendframework": {
   "n_advisories": 40,
   "n_malicious": 0,
   "n_real_cve": 40,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-2fhr-8r8r-qp56",
    "GHSA-5957-5crx-79jx",
    "GHSA-5957-5crx-79jx",
    "GHSA-5gmf-3c43-q73v"
   ],
   "sample_summary": "ZendFramework Information Disclosure and Insufficient Entropy vulnerability"
  },
  "swiftmailer/swiftmailer": {
   "n_advisories": 3,
   "n_malicious": 0,
   "n_real_cve": 3,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-4qpj-gxxg-jqg4",
    "GHSA-pr44-4jfr-286m",
    "GHSA-wjv8-pxr6-5f4r"
   ],
   "sample_summary": "Swiftmailer Sendmail transport arbitrary shell execution"
  },
  "facade/ignition": {
   "n_advisories": 8,
   "n_malicious": 0,
   "n_real_cve": 8,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-4qwp-7c67-jmcc",
    "GHSA-4qwp-7c67-jmcc",
    "GHSA-4qwp-7c67-jmcc",
    "GHSA-4qwp-7c67-jmcc"
   ],
   "sample_summary": "Unauthenticated remote code execution in Ignition"
  },
  "namshi/jose": {
   "n_advisories": 5,
   "n_malicious": 0,
   "n_real_cve": 5,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-4rr6-gf59-ggw5",
    "GHSA-hxhc-wmg8-xrqf",
    "GHSA-hxhc-wmg8-xrqf",
    "GHSA-hxhc-wmg8-xrqf"
   ],
   "sample_summary": "namshi/jose - Verification bypass"
  },
  "zendframework/zend-json": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-8x2v-pcg7-94f4",
    "GHSA-8x2v-pcg7-94f4"
   ],
   "sample_summary": "Zend-JSON vulnerable to XXE/XEE attacks"
  },
  "zendframework/zend-diactoros": {
   "n_advisories": 3,
   "n_malicious": 0,
   "n_real_cve": 3,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-f6p5-76fp-m248",
    "GHSA-fq4p-86hh-42v9",
    "GHSA-rh3c-7wqx-6w95"
   ],
   "sample_summary": "URL Rewrite vulnerability in multiple zendframework components"
  },
  "zendframework/zend-feed": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-f6p5-76fp-m248",
    "GHSA-jmmp-vh96-78rm"
   ],
   "sample_summary": "URL Rewrite vulnerability in multiple zendframework components"
  },
  "components/jquery": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-gxr4-xjj5-5px2",
    "GHSA-jpcq-cgw6-v4j6"
   ],
   "sample_summary": "Potential XSS vulnerability in jQuery"
  },
  "zendframework/zend-cache": {
   "n_advisories": 2,
   "n_malicious": 0,
   "n_real_cve": 2,
   "any_with_version_range": true,
   "sample_ids": [
    "GHSA-pw5c-xqf2-6xc2",
    "GHSA-pw5c-xqf2-6xc2"
   ],
   "sample_summary": "Doctrine Security Misconfiguration Vulnerability"
  }
 }
}