
The breakdown of the 6 CVEs discovered and responsibly disclosed by our team: • CVE-2026-44284 & 44285 (CRITICAL): Prototype pollution & RCE via schema loading/code generation • CVE-2026-44287, 44289, 44291 (HIGH): DoS & Prototype pollution during decoding • CVE-2026-44293 (MED): Unsafe descriptor handling
Post summary
The team has responsibly disclosed six new CVEs, detailing each vulnerability’s type and severity, including prototype pollution, RCE, DoS, and unsafe descriptor handling.

