CVEs affecting projects tracked on Release Alert, from NVD & OSV.
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases