CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service