CVEs affecting projects tracked on Release Alert, from NVD & OSV.
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.