Executive assessment
Today's brief leads with Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 01 should lead instead of Finding 06 because it is critical, enables admin session forgery and RCE, and is the only finding listed with in-the-wild exploitation. Themes: Remote code and command execution; Windows path traversal edge cases; Untrusted input reaching parsers and deserialisers. Patch order: Finding 01 (Critical with in-the-wild exploitation; set an explicit strong COOKIE_SIGN_KEYS value because no fixed version is listed); Finding 03 (Critical Seroval vulnerabilities with fixes listed in 1.6.2 and 1.6.3, and controls for attacker-controlled JSON deserialisation); Finding 04 (Critical IP spoofing issue with proxy-addr 2.0.8 or later available); Finding 07 (High severity with proof-of-concept exploitation and API gateway or endpoint restrictions available); Finding 08 (High severity OS command injection in the @nx/docker release pipeline with fixed versions listed for both supported lines).
Finding 01 — Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
What changed: A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and (Unconfirmed, single-source.)
Technical evidence: CVE-2026-61500; CVSS v4.0 9.3; weakness CWE-338; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Set an explicit strong COOKIE_SIGN_KEYS value to mitigate signing-key prediction. VulnCheck reports exploitation attempts detected on 1 October 2026 and an unnamed actor in China targeting real vulnerable hosts in the US. ([github.com](https://github.com/aramosf/CVE-2026-61500), [thehackernews.com](https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html))
Affected: HFS 3.0.0 through 3.2.0. ([github.com](https://github.com/aramosf/CVE-2026-61500))
Action: Map CVE-2026-61500 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: thehackernews.com](https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html)
Finding 02 — Multiple vulnerabilities in simple-git
What changed: simple-git carries 5 CVEs across 3 advisories: OS Command Injection; Command execution through unblocked Git configuration includes; VISUAL editor environment variable is omitted from unsafe editor detection. CVE coverage: CVE-2026-102829, CVE-2026-102827, CVE-2026-28291, CVE-2026-102828, CVE-2026-102826.
Technical evidence: CVE-2026-102829; CVSS v4.0 9.2; weakness CWE-78, CWE-184; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-102829 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-v5rq-49vh-5v5c)
Finding 03 — Multiple vulnerabilities in Seroval
What changed: CVE coverage: CVE-2026-104846, CVE-2026-104845. The cited advisories disclose: fromJSON Promise thenable assimilation invokes plugin-produced callables; Memory exhaustion via unchecked TypedArray length in JSON deserialization.
Technical evidence: CVE-2026-104846; CVSS v3.1 9.8; weakness CWE-843; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Block attacker-controlled JSON from plugin-capable Seroval deserialisation. For fromJSON/fromCrossJSON, reject non-ArrayBuffer sources and cap allocation size. ([raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104846.json), [github.com](https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-p6vx-979v-rg4c), [github.com](https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-jp82-f5mq-hwhp))
Affected: CVE-2026-104846 affects seroval >= 0.12.0 through 1.6.0; CVE-2026-104845 affects versions <= 1.6.2. ([github.com](https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-p6vx-979v-rg4c), [github.com](https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-jp82-f5mq-hwhp))
Fix: CVE-2026-104846 is patched in 1.6.2; CVE-2026-104845 is patched in 1.6.3. ([github.com](https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-p6vx-979v-rg4c), [github.com](https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-jp82-f5mq-hwhp))
Action: Map CVE-2026-104846 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-p6vx-979v-rg4c)
Finding 04 — proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
What changed: GitHub Advisory Database published GHSA-jqcg-44mw-7w3h for CVE-2026-90711 (proxy-addr): Authentication Bypass by Spoofing, CVSS v3.1 9.1; affected: proxy-addr versions 1.1.0 through 2.0.7.
Technical evidence: CVE-2026-90711; CVSS v3.1 9.1; weakness CWE-290, CWE-348, CWE-697; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Ensure IPv4-mapped IPv6 trust subnets use a prefix length of at least 97, or express the range in plain IPv4 notation. CISA ADP Vulnrichment reports no exploitation. ([raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/90xxx/CVE-2026-90711.json))
Affected: proxy-addr versions 1.1.0 through 2.0.7. ([raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/90xxx/CVE-2026-90711.json))
Fix: proxy-addr 2.0.8 or later. ([raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/90xxx/CVE-2026-90711.json))
Action: Map CVE-2026-90711 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-jqcg-44mw-7w3h)
Finding 05 — W (vincent-peugnet/wcms): Unrestricted Upload of File with Dangerous Type
What changed: W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[:path].
Technical evidence: CVE-2026-105123; CVSS v4.0 8.7; weakness CWE-434; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Allow-list upload extensions, reject php, phtml, phar and .htaccess files, enforce a realpath jail, and store uploads outside the document root. ([github.com](https://github.com/vincent-peugnet/wcms/issues/662), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-105123))
Action: Map CVE-2026-105123 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-105123)
Finding 06 — Multiple vulnerabilities in UTMStack
What changed: CVE coverage: CVE-2026-82039, CVE-2026-82044. The cited advisories disclose: an SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format.
Technical evidence: CVE-2026-82039; CVSS v4.0 8.7; weakness CWE-89; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: NVD records CISA Coordinator SSVC assessments of 'exploitation: none' for both CVEs. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-82039), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-82044))
Panel assessment: Patch this week: authenticated access and no reported exploitation lower the immediate exposure, but the SQL injection has high blast radius because it can execute arbitrary SQL with DBA privileges, enabling full database read, data modification, and potential filesystem access. (priority: this week)
Action: Map CVE-2026-82039 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-82039)
Finding 07 — OpenStack Aodh and Watcher: Function Call With Incorrect Variable or Reference as Argument
What changed: Chen YuXiang discovered that OpenStack Aodh did not correctly enforce project scoping in its alarm list API and that the OpenStack Watcher webhook trigger endpoint did not apply authorization. An attacker could possibly use this issue to access sensitive alarm metadata or trigger unauthorized action plans.
Technical evidence: CVE-2026-76878; CVSS v4.0 8.4; weakness CWE-688; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Block Aodh alarm-list requests where all_projects=false at the API gateway. Restrict the Watcher webhook endpoint so it is not accessible to end users. OpenStack's Launchpad report publishes a proof of concept using two disposable projects and a project-A reader. ([security.openstack.org](https://security.openstack.org/ossa/OSSA-2026-036.html), [launchpad.net](https://launchpad.net/bugs/2161276), [launchpad.net](https://launchpad.net/bugs/2161771), +1 more)
Fix: 26.04 LTS resolute python3-aodh – 1:22.0.0-0ubuntu1.1 python3-watcher – 2:16.0.0-0ubuntu1+esm1; 24.04 LTS noble python3-aodh – 1:18.0.0-0ubuntu1.1 python3-watcher – 2:12.0.0-0ubuntu1.3+esm1. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8870-1))
Panel assessment: Patch now where Aodh or Watcher is in use: the issue combines high severity, a public Aodh proof of concept and tenant-facing API behaviour that can cross project boundaries or trigger unauthorised operational actions. The likely path is a project reader abusing Aodh alarm-list scoping with all_projects=false to reach other projects' alarm metadata, or an end user invoking Watcher's webhook endpoint to start action plans without authorisation. (priority: patch now)
Action: Map CVE-2026-76878 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8870-1)
Finding 08 — @nx/docker: OS command injection in the @nx/docker release pipeline
What changed: GitHub Advisory Database published GHSA-6vc5-vf29-ffr2 for CVE-2026-104859 (@nx/docker): OS Command Injection, CVSS v4.0 7.3.
Technical evidence: CVE-2026-104859; CVSS v4.0 7.3; weakness CWE-78; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Avoid running a Docker release against any repository whose Nx configuration you do not control or whose configuration a pull request has changed; do not treat --dry-run as protective. If untrusted configuration was used with nx release version, delete the generated Docker version file before the next publish. The Nx security advisory reports that it has no evidence of exploitation in the wild. ([github.com](https://github.com/nrwl/nx/security/advisories/GHSA-6vc5-vf29-ffr2))
Fix: @nx/docker 22.7.8 (22.x line) and 23.1.1 (23.x line), or later. ([github.com](https://github.com/nrwl/nx/security/advisories/GHSA-6vc5-vf29-ffr2))
Action: Map CVE-2026-104859 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-6vc5-vf29-ffr2)
Finding 09 — Multiple vulnerabilities in vLLM
What changed: CVE coverage: CVE-2026-105753, CVE-2026-105752, CVE-2026-105758, CVE-2026-105760, CVE-2026-105754, CVE-2026-105757, CVE-2026-105755, CVE-2026-105756. The cited advisories disclose: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core; Harmony tool continuations drop cache_salt — restoring a cross-tenant prefix-cache membership oracle; Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach; GLMGA video sampling permits request-driven CPU and memory exhaustion; Scale-out disaggregated multimodal transport trusts caller-supplied features; Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service; Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on /score and /rerank; Loose cache_salt validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream ValueError denial of service.
Technical evidence: CVE-2026-105753; CVSS v3.1 6.5; weakness CWE-617; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: For the video-sampling issues, remove or filter request-level video_backend, fps and max_frames at the gateway, and do not allow untrusted callers to select GLMGA. Apply authentication, rate limiting, request concurrency limits and process memory isolation, or use a separate constrained media-loading worker pool. ([github.com](https://github.com/advisories/GHSA-ph3r-5jfg-f84f), [github.com](https://github.com/advisories/GHSA-935w-9g4m-p28p), [github.com](https://github.com/advisories/GHSA-x6mc-67gf-chw4), +5 more)
Affected: CVE-2026-105753: vllm <0.28.0; CVE-2026-105758: vllm >=0.24.0 and <0.30.0; CVE-2026-105760: vllm >=0.23.0rc2 and <0.30.0; all other listed CVEs: vllm <0.30.0. ([github.com](https://github.com/advisories/GHSA-ph3r-5jfg-f84f), [github.com](https://github.com/advisories/GHSA-935w-9g4m-p28p), [github.com](https://github.com/advisories/GHSA-x6mc-67gf-chw4), +5 more)
Fix: CVE-2026-105753: vllm 0.28.0; all other listed CVEs: vllm 0.30.0. ([github.com](https://github.com/advisories/GHSA-ph3r-5jfg-f84f), [github.com](https://github.com/advisories/GHSA-935w-9g4m-p28p), [github.com](https://github.com/advisories/GHSA-x6mc-67gf-chw4), +5 more)
Action: Map CVE-2026-105753 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-ph3r-5jfg-f84f)
Finding 10 — Werkzeug: Improper Handling of Windows Device Names
What changed: GitHub Advisory Database published GHSA-g6x2-hccm-hh4m for CVE-2026-102598 (Werkzeug): Improper Handling of Windows Device Names, CVSS v4.0 6.3; affected: Werkzeug versions before 3.1.9.
Technical evidence: CVE-2026-102598; CVSS v4.0 6.3; weakness CWE-67; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Reject requested paths ending with a Windows special device name that has an empty ADS marker, such as NUL:, before they reach send_from_directory(). Monitor for these paths and indefinitely hung reads. ([github.com](https://github.com/advisories/GHSA-g6x2-hccm-hh4m))
Affected: Werkzeug versions before 3.1.9. ([github.com](https://github.com/advisories/GHSA-g6x2-hccm-hh4m))
Fix: Werkzeug 3.1.9. ([github.com](https://github.com/advisories/GHSA-g6x2-hccm-hh4m))
Action: Map CVE-2026-102598 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-g6x2-hccm-hh4m)
Finding 11 — Filament: Missing Authentication for Critical Function
What changed: GitHub Advisory Database published GHSA-7m6h-rg42-m449 for CVE-2026-104181 (Filament): Missing Authentication for Critical Function, CVSS v3.1 5.4.
Technical evidence: CVE-2026-104181; CVSS v3.1 5.4; weakness CWE-306; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Until patched, disable app-based MFA and use Filament's email-authentication method instead; the advisory states email-based MFA is unaffected. If app MFA must remain enabled, monitor and alert on app-MFA setup or disablement and recovery-code generation or regeneration. CISA's Vulnrichment record reports exploitation as 'none'. ([github.com](https://github.com/filamentphp/filament/security/advisories/GHSA-7m6h-rg42-m449), [filamentphp.com](https://filamentphp.com/docs/4.x/users/multi-factor-authentication), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-104181))
Fix: 4.13.3 and 5.8.3. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-104181))
Action: Map CVE-2026-104181 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-7m6h-rg42-m449)
Finding 12 — uv: Path traversal on Windows through wheel extraction
What changed: GitHub Advisory Database published GHSA-2cv4-cqwr-gwf7 for CVE-2026-104843 (uv): Path Traversal, CVSS v4.0 5.9; affected: >= 0.12.7, < 0.12.18 on Windows.
Technical evidence: CVE-2026-104843; CVSS v4.0 5.9; weakness CWE-22; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Affected: >= 0.12.7, < 0.12.18 on Windows ([github.com](https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7))
Fix: >= 0.12.18 ([github.com](https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7))
Action: Map CVE-2026-104843 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-2cv4-cqwr-gwf7)
Finding 13 — Mako: Path traversal via drive-letter URI on Windows in TemplateLookup
What changed: GitHub Advisory Database published GHSA-5639-2j2p-m4mx for CVE-2026-102991 (Mako): Path Traversal, CVSS v3.1 6.5; affected: Mako versions earlier than 1.4.2 are affected.
Technical evidence: CVE-2026-102991; CVSS v3.1 6.5; weakness CWE-22; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Until patched, reject drive-designator URIs before they reach TemplateLookup.get_template(), including in query strings, form or JSON bodies, route parameters and dynamic include expressions. CISA Coordinator classifies exploitation as 'poc'. ([osv.dev](https://osv.dev/vulnerability/GHSA-5639-2j2p-m4mx), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-102991))
Affected: Mako versions earlier than 1.4.2 are affected. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-102991))
Fix: Mako 1.4.2. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-102991))
Action: Map CVE-2026-102991 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-5639-2j2p-m4mx)
Finding 14 — PostCSS: Uncontrolled Resource Consumption
What changed: GitHub Advisory Database published GHSA-rj75-hqrm-r3gf for CVE-2026-104844 (PostCSS): Uncontrolled Resource Consumption, CVSS v3.1 5.9; affected: Versions earlier than 7.1.6.
Technical evidence: CVE-2026-104844; CVSS v3.1 5.9; weakness CWE-400, CWE-407; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Cap the size of selectors accepted from untrusted sources before parsing. The CISA Coordinator's SSVC assessment reports exploitation as "none". ([api.osv.dev](https://api.osv.dev/v1/vulns/GHSA-rj75-hqrm-r3gf), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-104844))
Affected: Versions earlier than 7.1.6. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-104844))
Fix: 7.1.6. ([api.osv.dev](https://api.osv.dev/v1/vulns/GHSA-rj75-hqrm-r3gf))
Action: Map CVE-2026-104844 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-rj75-hqrm-r3gf)
Finding 15 — Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows
What changed: GitHub Advisory Database published GHSA-7g7c-h8rr-7p6q for CVE-2026-104871 (Angular SSR): Path Traversal, CVSS v4.0 6.3.
Technical evidence: CVE-2026-104871; CVSS v4.0 6.3; weakness CWE-22; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: For affected Windows deployments, sanitise request URLs before CommonEngine.render by replacing backslashes or constructing an absolute HTTP URL. Alternatively, migrate from CommonEngine to AngularNodeAppEngine. NVD records the CISA Coordinator's SSVC assessment as 'exploitation: none'. ([github.com](https://github.com/angular/angular-cli/security/advisories/GHSA-7g7c-h8rr-7p6q), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-104871))
Fix: Versions <= 19.2.27 have reached End of Support / LTS expiration and will not be patched ([github.com](https://github.com/angular/angular-cli/security/advisories/GHSA-7g7c-h8rr-7p6q))
Action: Map CVE-2026-104871 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-7g7c-h8rr-7p6q)