A stored cross-site scripting (XSS) vulnerability exists in fastschema through v0.15.1, allowing low-privileged authenticated users to upload SVG files containing malicious JavaScript by bypassing MIME type checks. This could enable attackers to execute malicious JavaScript on other users' browsers. The vulnerability impacts fastschema installations, particularly those with low-privileged authenticated us [truncated]
The CVE-2026-72582 record describes a NULL pointer dereference vulnerability in the fastschema library through version 0.15.1. This vulnerability allows an unauthenticated remote attacker to crash the server process with a single HTTP request to the /api/auth/local/recover endpoint. The vulnerability is caused by an unchecked error path in the sendOTPEmail function within the pkg/auth/local.go file, which [truncated]