{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-27818",
        "tracking": {
            "current_release_date": "2026-03-23T10:27:31.561716Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-27818",
            "initial_release_date": "2026-02-26T00:25:36.395097Z",
            "revision_history": [
                {
                    "date": "2026-02-26T00:25:36.395097Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T00:25:38.549006Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-26T00:38:54.449356Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T00:39:00.301673Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-26T11:27:05.171599Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (59).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T11:27:15.164665Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-26T14:13:32.998610Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-26T14:13:34.523513Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-26T15:39:46.931826Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T15:39:54.194880Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-26T15:45:23.463941Z",
                    "number": "11",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-02-26T18:20:55.382886Z",
                    "number": "12",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T21:24:54.281009Z",
                    "number": "13",
                    "summary": "CVSS created.| Products created (1).| Product Identifiers created (1)."
                },
                {
                    "date": "2026-03-04T21:25:03.009470Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:39:42.775911Z",
                    "number": "15",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                }
            ],
            "status": "interim",
            "version": "15"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.0.3",
                                "product": {
                                    "name": "vers:unknown/<4.0.3",
                                    "product_id": "CSAFPID-5723293"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<4.0.3",
                                "product": {
                                    "name": "vers:unknown/>=0|<4.0.3",
                                    "product_id": "CSAFPID-5731456"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "terriajs-server"
                    }
                ],
                "category": "vendor",
                "name": "TerriaJS"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.0.3",
                                "product": {
                                    "name": "vers:unknown/<4.0.3",
                                    "product_id": "CSAFPID-5759376",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:terria:terriajs-server:*:*:*:*:*:node.js:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "terriajs-server"
                    }
                ],
                "category": "vendor",
                "name": "terria"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.0.8",
                                "product": {
                                    "name": "vers:unknown/0.0.8",
                                    "product_id": "CSAFPID-5727607"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.0",
                                "product": {
                                    "name": "vers:unknown/1.0.0",
                                    "product_id": "CSAFPID-5727608"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.0",
                                "product": {
                                    "name": "vers:unknown/1.1.0",
                                    "product_id": "CSAFPID-5727609"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.1",
                                "product": {
                                    "name": "vers:unknown/1.1.1",
                                    "product_id": "CSAFPID-5727610"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.2",
                                "product": {
                                    "name": "vers:unknown/1.1.2",
                                    "product_id": "CSAFPID-5727611"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.3",
                                "product": {
                                    "name": "vers:unknown/1.1.3",
                                    "product_id": "CSAFPID-5727612"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.0",
                                "product": {
                                    "name": "vers:unknown/1.2.0",
                                    "product_id": "CSAFPID-5727613"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.0",
                                "product": {
                                    "name": "vers:unknown/1.3.0",
                                    "product_id": "CSAFPID-5727614"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.0",
                                "product": {
                                    "name": "vers:unknown/1.4.0",
                                    "product_id": "CSAFPID-5727615"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.1",
                                "product": {
                                    "name": "vers:unknown/1.4.1",
                                    "product_id": "CSAFPID-5727616"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.0",
                                "product": {
                                    "name": "vers:unknown/2.0.0",
                                    "product_id": "CSAFPID-5727617"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0",
                                "product": {
                                    "name": "vers:unknown/2.1.0",
                                    "product_id": "CSAFPID-5727618"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.0",
                                "product": {
                                    "name": "vers:unknown/2.2.0",
                                    "product_id": "CSAFPID-5727619"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.1",
                                "product": {
                                    "name": "vers:unknown/2.2.1",
                                    "product_id": "CSAFPID-5727620"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.2",
                                "product": {
                                    "name": "vers:unknown/2.2.2",
                                    "product_id": "CSAFPID-5727621"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.0",
                                "product": {
                                    "name": "vers:unknown/2.3.0",
                                    "product_id": "CSAFPID-5727622"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.4.0",
                                "product": {
                                    "name": "vers:unknown/2.4.0",
                                    "product_id": "CSAFPID-5727623"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.0",
                                "product": {
                                    "name": "vers:unknown/2.5.0",
                                    "product_id": "CSAFPID-5727624"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.1",
                                "product": {
                                    "name": "vers:unknown/2.5.1",
                                    "product_id": "CSAFPID-5727625"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.0",
                                "product": {
                                    "name": "vers:unknown/2.6.0",
                                    "product_id": "CSAFPID-5727626"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.1",
                                "product": {
                                    "name": "vers:unknown/2.6.1",
                                    "product_id": "CSAFPID-5727627"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.2",
                                "product": {
                                    "name": "vers:unknown/2.6.2",
                                    "product_id": "CSAFPID-5727628"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.3",
                                "product": {
                                    "name": "vers:unknown/2.6.3",
                                    "product_id": "CSAFPID-5727629"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.4",
                                "product": {
                                    "name": "vers:unknown/2.6.4",
                                    "product_id": "CSAFPID-5727630"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.5",
                                "product": {
                                    "name": "vers:unknown/2.6.5",
                                    "product_id": "CSAFPID-5727631"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.6",
                                "product": {
                                    "name": "vers:unknown/2.6.6",
                                    "product_id": "CSAFPID-5727632"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.7",
                                "product": {
                                    "name": "vers:unknown/2.6.7",
                                    "product_id": "CSAFPID-5727633"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.0",
                                "product": {
                                    "name": "vers:unknown/2.7.0",
                                    "product_id": "CSAFPID-5727634"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.1",
                                "product": {
                                    "name": "vers:unknown/2.7.1",
                                    "product_id": "CSAFPID-5727635"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.2",
                                "product": {
                                    "name": "vers:unknown/2.7.2",
                                    "product_id": "CSAFPID-5727636"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.3",
                                "product": {
                                    "name": "vers:unknown/2.7.3",
                                    "product_id": "CSAFPID-5727637"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.4",
                                "product": {
                                    "name": "vers:unknown/2.7.4",
                                    "product_id": "CSAFPID-5727638"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.8.0",
                                "product": {
                                    "name": "vers:unknown/2.8.0",
                                    "product_id": "CSAFPID-5727639"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.9.0",
                                "product": {
                                    "name": "vers:unknown/2.9.0",
                                    "product_id": "CSAFPID-5727640"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.9.1",
                                "product": {
                                    "name": "vers:unknown/2.9.1",
                                    "product_id": "CSAFPID-5727641"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.9.2",
                                "product": {
                                    "name": "vers:unknown/2.9.2",
                                    "product_id": "CSAFPID-5727642"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.0",
                                "product": {
                                    "name": "vers:unknown/3.0.0",
                                    "product_id": "CSAFPID-5727643"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.0-test-1",
                                "product": {
                                    "name": "vers:unknown/3.0.0-test-1",
                                    "product_id": "CSAFPID-5727644"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.0-test-2",
                                "product": {
                                    "name": "vers:unknown/3.0.0-test-2",
                                    "product_id": "CSAFPID-5727645"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.0-test-3",
                                "product": {
                                    "name": "vers:unknown/3.0.0-test-3",
                                    "product_id": "CSAFPID-5727646"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.1",
                                "product": {
                                    "name": "vers:unknown/3.0.1",
                                    "product_id": "CSAFPID-5727647"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.0",
                                "product": {
                                    "name": "vers:unknown/3.1.0",
                                    "product_id": "CSAFPID-5727648"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.2.0",
                                "product": {
                                    "name": "vers:unknown/3.2.0",
                                    "product_id": "CSAFPID-5727649"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.3.0",
                                "product": {
                                    "name": "vers:unknown/3.3.0",
                                    "product_id": "CSAFPID-5727650"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.3.1",
                                "product": {
                                    "name": "vers:unknown/3.3.1",
                                    "product_id": "CSAFPID-5727651"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.3.2",
                                "product": {
                                    "name": "vers:unknown/3.3.2",
                                    "product_id": "CSAFPID-5727652"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.3.3",
                                "product": {
                                    "name": "vers:unknown/3.3.3",
                                    "product_id": "CSAFPID-5727653"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.3.4",
                                "product": {
                                    "name": "vers:unknown/3.3.4",
                                    "product_id": "CSAFPID-5727654"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.0.0",
                                "product": {
                                    "name": "vers:unknown/4.0.0",
                                    "product_id": "CSAFPID-5727655"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.0.0-alpha.1",
                                "product": {
                                    "name": "vers:unknown/4.0.0-alpha.1",
                                    "product_id": "CSAFPID-5727656"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.0.1",
                                "product": {
                                    "name": "vers:unknown/4.0.1",
                                    "product_id": "CSAFPID-5727657"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.0.2",
                                "product": {
                                    "name": "vers:unknown/4.0.2",
                                    "product_id": "CSAFPID-5727658"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/editor-spa",
                                "product": {
                                    "name": "vers:unknown/editor-spa",
                                    "product_id": "CSAFPID-5727659"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/editor-spa-2",
                                "product": {
                                    "name": "vers:unknown/editor-spa-2",
                                    "product_id": "CSAFPID-5727660"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.1",
                                "product": {
                                    "name": "vers:unknown/v1.1.1",
                                    "product_id": "CSAFPID-5727661"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.2",
                                "product": {
                                    "name": "vers:unknown/v1.1.2",
                                    "product_id": "CSAFPID-5727662"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.3",
                                "product": {
                                    "name": "vers:unknown/v1.1.3",
                                    "product_id": "CSAFPID-5727663"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.0",
                                "product": {
                                    "name": "vers:unknown/v1.2.0",
                                    "product_id": "CSAFPID-5727664"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.3.0",
                                "product": {
                                    "name": "vers:unknown/v1.3.0",
                                    "product_id": "CSAFPID-5727665"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "terriajs-server"
                    }
                ],
                "category": "vendor",
                "name": "terriajs"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-27818",
            "cwe": {
                "id": "CWE-918",
                "name": "Server-Side Request Forgery (SSRF)"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-27818"
                },
                {
                    "category": "description",
                    "text": "TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-27818"
                },
                {
                    "category": "description",
                    "text": "TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-27818.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "### Impact\nA validation bug allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration.\n\nThe validation only checks if a hostname _ended_ with an allowed domain. This meant:\n\nIf `example.com` is allowed in `proxyableDomains`:\n\n- ✅ example.com is allowed (correct)\n- ✅ api.example.com is allowed (correct)\n- ⚠️ maliciousexample.com is allowed (incorrect)\n\nAn attacker could register maliciousexample.com and proxy content through `terriajs-server`, bypassing proxy restrictions.\n\n### Patches\nAll versions up to 4.0.2 are affected. Upgrade to 4.0.3 to address the vulnerability.",
                    "title": "github - https://github.com/advisories/GHSA-w789-49fc-v8hr"
                },
                {
                    "category": "description",
                    "text": "### Impact\nA validation bug allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration.\n\nThe validation only checks if a hostname _ended_ with an allowed domain. This meant:\n\nIf `example.com` is allowed in `proxyableDomains`:\n\n- ✅ example.com is allowed (correct)\n- ✅ api.example.com is allowed (correct)\n- ⚠️ maliciousexample.com is allowed (incorrect)\n\nAn attacker could register maliciousexample.com and proxy content through `terriajs-server`, bypassing proxy restrictions.\n\n### Patches\nAll versions up to 4.0.2 are affected. Upgrade to 4.0.3 to address the vulnerability.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-w789-49fc-v8hr.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00095",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.7",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.4",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5723293",
                    "CSAFPID-5727607",
                    "CSAFPID-5727608",
                    "CSAFPID-5727609",
                    "CSAFPID-5727610",
                    "CSAFPID-5727611",
                    "CSAFPID-5727612",
                    "CSAFPID-5727613",
                    "CSAFPID-5727614",
                    "CSAFPID-5727615",
                    "CSAFPID-5727616",
                    "CSAFPID-5727617",
                    "CSAFPID-5727618",
                    "CSAFPID-5727619",
                    "CSAFPID-5727620",
                    "CSAFPID-5727621",
                    "CSAFPID-5727622",
                    "CSAFPID-5727623",
                    "CSAFPID-5727624",
                    "CSAFPID-5727625",
                    "CSAFPID-5727626",
                    "CSAFPID-5727627",
                    "CSAFPID-5727628",
                    "CSAFPID-5727629",
                    "CSAFPID-5727630",
                    "CSAFPID-5727631",
                    "CSAFPID-5727632",
                    "CSAFPID-5727633",
                    "CSAFPID-5727634",
                    "CSAFPID-5727635",
                    "CSAFPID-5727636",
                    "CSAFPID-5727637",
                    "CSAFPID-5727638",
                    "CSAFPID-5727639",
                    "CSAFPID-5727640",
                    "CSAFPID-5727641",
                    "CSAFPID-5727642",
                    "CSAFPID-5727643",
                    "CSAFPID-5727644",
                    "CSAFPID-5727645",
                    "CSAFPID-5727646",
                    "CSAFPID-5727647",
                    "CSAFPID-5727648",
                    "CSAFPID-5727649",
                    "CSAFPID-5727650",
                    "CSAFPID-5727651",
                    "CSAFPID-5727652",
                    "CSAFPID-5727653",
                    "CSAFPID-5727654",
                    "CSAFPID-5727655",
                    "CSAFPID-5727656",
                    "CSAFPID-5727657",
                    "CSAFPID-5727658",
                    "CSAFPID-5727659",
                    "CSAFPID-5727660",
                    "CSAFPID-5727661",
                    "CSAFPID-5727662",
                    "CSAFPID-5727663",
                    "CSAFPID-5727664",
                    "CSAFPID-5727665",
                    "CSAFPID-5731456",
                    "CSAFPID-5759376"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27818"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27818"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-27818"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/27xxx/CVE-2026-27818.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-27818.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-27818"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-w789-49fc-v8hr"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-w789-49fc-v8hr"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-w789-49fc-v8hr.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/TerriaJS/terriajs-server/commit/3aaa5d9717162b245ae4569232bbe7d8673c913f"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/TerriaJS/terriajs-server/security/advisories/GHSA-w789-49fc-v8hr"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27818.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27818"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/TerriaJS/terriajs-server/releases/tag/4.0.3"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-w789-49fc-v8hr"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-5723293",
                        "CSAFPID-5727607",
                        "CSAFPID-5727608",
                        "CSAFPID-5727609",
                        "CSAFPID-5727610",
                        "CSAFPID-5727611",
                        "CSAFPID-5727612",
                        "CSAFPID-5727613",
                        "CSAFPID-5727614",
                        "CSAFPID-5727615",
                        "CSAFPID-5727616",
                        "CSAFPID-5727617",
                        "CSAFPID-5727618",
                        "CSAFPID-5727619",
                        "CSAFPID-5727620",
                        "CSAFPID-5727621",
                        "CSAFPID-5727622",
                        "CSAFPID-5727623",
                        "CSAFPID-5727624",
                        "CSAFPID-5727625",
                        "CSAFPID-5727626",
                        "CSAFPID-5727627",
                        "CSAFPID-5727628",
                        "CSAFPID-5727629",
                        "CSAFPID-5727630",
                        "CSAFPID-5727631",
                        "CSAFPID-5727632",
                        "CSAFPID-5727633",
                        "CSAFPID-5727634",
                        "CSAFPID-5727635",
                        "CSAFPID-5727636",
                        "CSAFPID-5727637",
                        "CSAFPID-5727638",
                        "CSAFPID-5727639",
                        "CSAFPID-5727640",
                        "CSAFPID-5727641",
                        "CSAFPID-5727642",
                        "CSAFPID-5727643",
                        "CSAFPID-5727644",
                        "CSAFPID-5727645",
                        "CSAFPID-5727646",
                        "CSAFPID-5727647",
                        "CSAFPID-5727648",
                        "CSAFPID-5727649",
                        "CSAFPID-5727650",
                        "CSAFPID-5727651",
                        "CSAFPID-5727652",
                        "CSAFPID-5727653",
                        "CSAFPID-5727654",
                        "CSAFPID-5727655",
                        "CSAFPID-5727656",
                        "CSAFPID-5727657",
                        "CSAFPID-5727658",
                        "CSAFPID-5727659",
                        "CSAFPID-5727660",
                        "CSAFPID-5727661",
                        "CSAFPID-5727662",
                        "CSAFPID-5727663",
                        "CSAFPID-5727664",
                        "CSAFPID-5727665",
                        "CSAFPID-5731456",
                        "CSAFPID-5759376"
                    ]
                }
            ],
            "title": "CVE-2026-27818"
        }
    ]
}