Rack has a Directory Traversal via Rack:Directory. (CVE-2026-22860) Rack's Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href. (CVE-2026-25500)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2026-0075.json"