←back to thread

283 points summarity | 3 comments | | HN request time: 0.713s | source
1. ikmckenz ◴[] No.44368868[source]
Related: https://arstechnica.com/gadgets/2025/05/open-source-project-...
replies(1): >>44369989 #
2. moyix ◴[] No.44369989[source]
The main difference is that all of the vulnerabilities reported here are real, many quite critical (XXE, RCE, SQLi, etc.). To be fair there were definitely a lot of XSS, but the main reason for that is that it's a really common vulnerability.
replies(1): >>44373327 #
3. ikmckenz ◴[] No.44373327[source]
All of them are real? You have a 100% rate of reports closed as valid?