This repository was archived by the owner on Jul 13, 2026. It is now read-only.
Security: nl-portal/nl-portal-backend-libraries
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)GHSA-xm3x-9cfw-jhx4 published
Jun 18, 2026 by theo-ritenseModerate -
Document contents remained downloadable by any logged-in user until 3.0.3 (incomplete fix of CVE-2026-49463)GHSA-jr45-52cw-69h5 published
Jun 17, 2026 by theo-ritenseModerate -
GraphQL Playground/GraphiQL UI and schema introspection enabled by default in nl-portal-backend-libraries through 3.0.0GHSA-9m9w-2vqr-m384 published
Jun 3, 2026 by Tom-RitenseModerate -
Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries through 3.0.0GHSA-qpm9-h556-mwxm published
Jun 3, 2026 by Tom-RitenseModerate -
IDOR allows any authenticated user to complete and tamper with another user's taak in nl-portal-backend-libraries 1.5.0 through 3.0.0GHSA-6h3c-r723-7fx3 published
Jun 3, 2026 by Tom-RitenseHigh