{"type":"bundle","id":"bundle--5c2aa103-9728-5d06-a578-d1949e585d7a","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--0f131e37-1e98-599c-a83f-27aba806496a","created":"2026-09-20T19:16:48.064Z","modified":"2026-09-20T19:16:48.064Z","name":"@fastify/oauth2 login CSRF via plantable state cookies","description":"@fastify/oauth2 is affected by login CSRF via plantable state cookies. Upgrade to the patched release.","aliases":["CVE-2026-18165"],"first_seen":"2026-08-15T00:00:00.000Z","last_seen":"2026-08-15T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"NVD CVE-2026-18165","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18165"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-18165-fastify-oauth2-login-csrf"},{"source_name":"CVE Record CVE-2026-18165","url":"https://www.cve.org/CVERecord?id=CVE-2026-18165"}]}]}