<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://orbisappsec.com</loc>
<lastmod>2026-09-30T00:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://orbisappsec.com/faq</loc>
<lastmod>2026-09-29T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/support</loc>
<lastmod>2026-09-29T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://orbisappsec.com/privacy-policy</loc>
<lastmod>2026-08-24T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://orbisappsec.com/terms-of-service</loc>
<lastmod>2026-08-24T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://orbisappsec.com/editorial-policy</loc>
<lastmod>2026-10-02T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://orbisappsec.com/authors/anupam-mediratta</loc>
<lastmod>2026-10-02T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/command-injection</loc>
<lastmod>2026-09-09T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.85</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/buffer-overflow</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.85</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/file-upload-security</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.85</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/integer-overflow</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.85</priority>
</url>
<url>
<loc>https://orbisappsec.com/reference</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://orbisappsec.com/reference/dom-xss-innerhtml</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://orbisappsec.com/reference/c-string-buffer-overflow</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://orbisappsec.com/reference/os-command-injection</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://orbisappsec.com/reference/path-traversal</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://orbisappsec.com/reference/insecure-deserialization</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://orbisappsec.com/reference/ssrf</loc>
<lastmod>2026-09-08T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://orbisappsec.com/ai-security-scanner</loc>
<lastmod>2026-06-02T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://orbisappsec.com/semgrep-alternative</loc>
<lastmod>2026-06-02T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.85</priority>
</url>
<url>
<loc>https://orbisappsec.com/github-security-pr-automation</loc>
<lastmod>2026-09-09T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.85</priority>
</url>
<url>
<loc>https://orbisappsec.com/snyk-alternative</loc>
<lastmod>2026-06-23T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.85</priority>
</url>
<url>
<loc>https://orbisappsec.com/github-advanced-security-alternative</loc>
<lastmod>2026-06-23T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.85</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog</loc>
<lastmod>2026-10-03T10:56:58.403Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-22</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-78</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-79</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-89</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-120</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-190</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-416</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-434</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-476</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/glossary/cwe-787</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/adm-zip-0-6-0-preserves-suid-bits-from-zips-cve-2026</loc>
<lastmod>2026-10-03T10:56:58.403Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/requestinput-type-confusion-nan-and-object-bypass-in-javascript</loc>
<lastmod>2026-10-02T22:53:00.183Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/undici-8-10-0-cache-poisoning-cve-2026-85152-auth-bypass</loc>
<lastmod>2026-10-02T22:52:04.817Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/pet-window-js-dynamic-code-evaluation-cwe-94-hardening-via-number</loc>
<lastmod>2026-10-02T22:51:25.004Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/sanitizeunicodeinput-fullwidth-u-bypasses-codepoint-validation</loc>
<lastmod>2026-10-02T22:50:08.693Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/voice-assistant-widget-xss-unsanitized-bot-messages-execute</loc>
<lastmod>2026-10-02T17:09:09.463Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/no-rate-limit-on-api-uploads-presign-enables-dos</loc>
<lastmod>2026-10-02T17:08:37.387Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/brace-expansion-stack-exhaustion-cve-2026-102276-patched</loc>
<lastmod>2026-10-02T17:05:59.309Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/hybridauth-telegram-oauth-timing-attack-in-authenticatecheckerror</loc>
<lastmod>2026-10-02T17:05:22.344Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/undici-7-29-0-tls-bypass-balancedpool-drops-connect-options</loc>
<lastmod>2026-10-02T17:04:48.991Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/axios-1-18-1-cve-2026-101898-http-2-ignores-proxy</loc>
<lastmod>2026-10-02T17:03:38.040Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/webapp-testing-server-script-shell-injection-via-unquoted-command</loc>
<lastmod>2026-10-01T19:13:17.734Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/aardvark-cef-process-core-shared-memory-handler-unvalidated-memcpy</loc>
<lastmod>2026-10-01T19:13:02.309Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/js-yaml-5-2-1-dos-exponential-parsing-in-flow-collections</loc>
<lastmod>2026-10-01T13:49:31.647Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/cve-2026-54673-builder-util-runtime-leaks-auth-headers-on-redirect</loc>
<lastmod>2026-10-01T13:47:46.378Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/cve-2026-73089-browserslist-4-28-1-dos-via-query-result-caching</loc>
<lastmod>2026-10-01T13:46:09.613Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/model-fetching-without-integrity-verification-in-onnx-loading</loc>
<lastmod>2026-10-01T13:45:35.610Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/navbar-html-injection-via-innerhtml-in-loadnavbar-js</loc>
<lastmod>2026-10-01T13:45:07.516Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/addsourceinput-javascript-url-injection-in-source-list-handler</loc>
<lastmod>2026-10-01T13:43:48.441Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/getcheckboxstring-html-injection-via-midi-metadata</loc>
<lastmod>2026-10-01T13:42:44.551Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/node-js-auth-query-sql-injection-via-group-code-interpolation</loc>
<lastmod>2026-10-01T13:40:57.996Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/location-search-xss-in-index-html-unsanitized-query-rendering</loc>
<lastmod>2026-10-01T13:37:55.820Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/php-session-start-missing-secure-cookie-flags-in-lasturl-php</loc>
<lastmod>2026-10-01T13:37:24.713Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/validateinput-false-on-settingscontroller-index-enables-stored-xss</loc>
<lastmod>2026-10-01T13:36:25.784Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/image-size-1-2-1-dos-zero-valued-dimensions-in-image-buffer</loc>
<lastmod>2026-09-30T17:27:05.010Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/path-resolve-path-traversal-in-node-cli-s-dynamic-import</loc>
<lastmod>2026-09-30T05:02:39.262Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/thinx-device-platform-command-injection-via-source-owner-in-git-fetch</loc>
<lastmod>2026-09-30T05:01:25.103Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/linkify-it-5-0-1-mailto-link-parsing-causes-dos</loc>
<lastmod>2026-09-30T05:00:09.847Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/slim-cli-unverified-remote-fetch-in-version-check</loc>
<lastmod>2026-10-01T13:48:17.339Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/toolforge-database-creation-sql-injection-via-unicode-backtick-bypass</loc>
<lastmod>2026-09-30T04:58:26.782Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/cloudflare-worker-reverse-proxy-ssrf-via-string-concatenation</loc>
<lastmod>2026-09-30T04:57:58.449Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/xshmgetimage-heap-corruption-unvalidated-image-height-in-streamproxy</loc>
<lastmod>2026-09-30T04:55:47.641Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/ensuretrivy-cwe-494-unverified-trivy-binary-download</loc>
<lastmod>2026-09-30T04:55:19.767Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/tung-tung-tracker-admin-api-missing-authentication-in-api-sync</loc>
<lastmod>2026-09-29T17:17:39.364Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/fast-uri-3-1-2-idn-host-bypass-cve-2026-13676-upgrade</loc>
<lastmod>2026-09-29T17:16:18.006Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/sgx-enclave-ecall-store-data-memcpy-buffer-overflow-in-256-byte</loc>
<lastmod>2026-09-29T17:15:18.092Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/xmldom-xmldom-0-9-10-redos-cve-2026-83606-in-pi-parsing</loc>
<lastmod>2026-09-29T04:15:16.711Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/bookdir-path-traversal-via-unsanitized-bookid-parameter</loc>
<lastmod>2026-09-28T21:28:34.035Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/boardcards-js-parseargs-ssrf-board-flag-reaches-metadata-ips</loc>
<lastmod>2026-09-28T21:26:45.342Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/unbounded-map-in-createloginratelimiter-exhausts-api-memory</loc>
<lastmod>2026-09-28T09:23:38.225Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/nanoid-3-3-11-integer-overflow-predictable-id-generation</loc>
<lastmod>2026-09-28T09:23:08.489Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/bff-proxy-qr-code-endpoint-prototype-pollution-via-unvalidated-json</loc>
<lastmod>2026-09-28T09:23:01.905Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/fetch-with-automatic-redirects-leaks-https-trust-to-api-tomys-top</loc>
<lastmod>2026-09-28T09:21:33.283Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/anthropic-api-adapter-prototype-pollution-in-parsetoolcallinput</loc>
<lastmod>2026-09-27T09:14:58.856Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/js-yaml-4-3-1-denial-of-service-malformed-input-hangs-yaml</loc>
<lastmod>2026-09-30T05:02:45.043Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/express-app-get-wildcard-handler-path-traversal-in-watch-js</loc>
<lastmod>2026-10-03T10:55:30.483Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/cve-2026-54290-hono-cors-reflects-any-origin-with-credentials</loc>
<lastmod>2026-09-26T21:12:53.200Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/innerhtml-injection-in-postalert-glitch-me-data-renders-unsanitized</loc>
<lastmod>2026-09-26T21:10:44.323Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/updater-parseupdate-cwe-494-unsigned-metadata-download</loc>
<lastmod>2026-09-26T21:09:20.376Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/post-api-generate-lacks-authentication-allowing-unauthenticated</loc>
<lastmod>2026-09-25T21:02:42.400Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/escapequotes-gap-lets-file-names-xss-search-results</loc>
<lastmod>2026-09-25T21:02:38.167Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/brace-expansion-dos-exponential-backtracking-in-nested-brace-patterns</loc>
<lastmod>2026-09-30T17:26:00.381Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/smol-toml-1-7-0-dos-malformed-toml-documents-crash-parser</loc>
<lastmod>2026-09-25T15:23:59.925Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/yandex-translate-api-key-leaked-via-url-query-parameter</loc>
<lastmod>2026-10-02T22:51:24.625Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/load-localstorage-js-json-parse-prototype-pollution-via-proto</loc>
<lastmod>2026-09-25T15:22:29.984Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/generateuuid-ditches-md5-for-sha-256-to-fix-cwe-328</loc>
<lastmod>2026-09-25T15:21:20.886Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/chrome-runtime-onmessage-missing-sender-validation-in-extension</loc>
<lastmod>2026-09-25T15:19:49.898Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/google-generative-ai-keys-exposed-in-client-side-fetch-urls</loc>
<lastmod>2026-09-25T15:18:38.147Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/backtest-js-cli-args-unvalidated-days-and-start-options</loc>
<lastmod>2026-09-25T15:16:26.809Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/api-url-defaults-to-http-without-https-enforcement</loc>
<lastmod>2026-09-25T15:21:52.873Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/knx-project-extractor-zip-bomb-unbounded-decompression-before-size</loc>
<lastmod>2026-09-25T15:15:21.586Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/meta-get-honored-uploadurl-from-script-headers-ssrf-fix</loc>
<lastmod>2026-09-25T15:14:27.157Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/unvalidated-thumbnailurl-passed-to-axios-get-ssrf-risk</loc>
<lastmod>2026-09-24T20:53:12.026Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/esearch-ssrf-requests-get-trusted-any-host-in-the-url</loc>
<lastmod>2026-10-01T13:38:32.100Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/josmfilehack-transformerfactory-xxe-external-dtd-processing-enabled</loc>
<lastmod>2026-09-24T04:54:17.110Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/tauri-type-text-command-injection-via-control-characters</loc>
<lastmod>2026-09-24T04:51:55.560Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/spring-boot-actuator-wildcard-exposure-in-2021-04-provisioning</loc>
<lastmod>2026-09-23T16:50:08.705Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/schedulepush-disablereminder-missing-authorization-check-in-push-js</loc>
<lastmod>2026-09-23T16:48:48.892Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/boardroom-server-handler-missing-authentication-on-http-endpoints</loc>
<lastmod>2026-09-23T04:45:10.762Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/updatecardbg-follows-unvalidated-302-location-headers</loc>
<lastmod>2026-09-22T16:41:44.410Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/runstreaming-command-injection-defense-in-depth-for-electron-child</loc>
<lastmod>2026-09-22T16:41:08.878Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heatmap-php-sql-injection-request-parameters-in-unparameterized</loc>
<lastmod>2026-09-22T04:36:58.488Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/docker-rpc-uc-command-injection-unsanitized-rpc-parameters</loc>
<lastmod>2026-09-21T04:29:18.583Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/markitdown-bridge-py-path-traversal-arbitrary-file-read-via-sys-argv</loc>
<lastmod>2026-09-20T16:23:36.966Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/stream-media-file-ssrf-src-parameter-reaches-requests-get</loc>
<lastmod>2026-09-20T16:22:55.781Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/http-client-danger-accept-invalid-certs-permitted-mitm-credential</loc>
<lastmod>2026-09-18T23:17:52.121Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/sample-placeholder-in-shlex-split-lets-filenames-inject-args</loc>
<lastmod>2026-09-18T23:16:56.839Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/jwt-authentication-disabled-signature-validation</loc>
<lastmod>2026-09-18T23:16:35.974Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/actual-budget-addtransaction-sh-sql-injection-via-shell-variable</loc>
<lastmod>2026-09-18T23:15:55.290Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/shacl-viewer-path-traversal-in-graph3d-unvalidated-path</loc>
<lastmod>2026-09-18T11:13:06.241Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/datatables-rowgroup-startrender-xss-via-unescaped-group-data</loc>
<lastmod>2026-09-17T23:09:26.923Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/package-abridge-js-command-injection-via-unsanitized-cli-arguments</loc>
<lastmod>2026-09-24T20:54:47.332Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/shell-quote-1-8-3-line-terminator-command-injection-cve-2026-9277</loc>
<lastmod>2026-09-30T17:25:21.982Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/fs-readfilesync-process-argv-2-path-traversal-in-zola-build</loc>
<lastmod>2026-09-17T07:23:10.017Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/write-page-jobs-unvalidated-page-dir-escapes-the-run-dir</loc>
<lastmod>2026-09-16T10:56:22.088Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/voice-assistant-command-injection-via-os-system-f-string</loc>
<lastmod>2026-10-02T17:04:21.192Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/requests-get-delete-post-with-verify-false-in-release</loc>
<lastmod>2026-09-16T10:55:20.934Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/ldap-filter-injection-in-da-unique-email-validator-fixed</loc>
<lastmod>2026-09-13T15:04:35.693Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/externalhttpclient-request-sent-basic-auth-over-plain-http</loc>
<lastmod>2026-09-13T04:28:10.997Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/modelexporter-js-path-traversal-via-unsanitized-directory-concatenation</loc>
<lastmod>2026-09-12T15:22:47.618Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/sql-s-insert-and-update-methods-used-f-string-interpolation-in-u2share</loc>
<lastmod>2026-09-12T15:22:11.182Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/installplugin-unvalidated-npm-package-names-reach-npm-install</loc>
<lastmod>2026-09-12T15:21:32.863Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/deletenestedproperty-prototype-pollution-via-dot-notation-path</loc>
<lastmod>2026-09-11T21:12:28.112Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/trackoptionsmanager-ddl-template-literal-sql-injection-closed</loc>
<lastmod>2026-09-19T11:19:23.242Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/eval-in-async-function-constructor-enables-runtime-escape</loc>
<lastmod>2026-09-11T09:09:52.894Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-via-template-literals-happens-in-node-js-sqlite</loc>
<lastmod>2026-09-10T00:48:51.596Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-stored-xss-happens-in-tinymce-plugins-and-how-to-fix-it</loc>
<lastmod>2026-09-09T12:44:37.526Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-credential-leakage-through-console-logging-happens-in-javascript-browser-extensions</loc>
<lastmod>2026-09-09T12:44:03.933Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-css-injection-via-weak-pattern-validation-happens-in-vue-js</loc>
<lastmod>2026-09-09T12:42:48.482Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-secrets-compromise-authentication-in-javascript-and-how-to-fix-it</loc>
<lastmod>2026-09-09T12:42:47.308Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unvalidated-dynamic-component-loading-happens-in-typescript-viewi</loc>
<lastmod>2026-09-09T12:42:24.477Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insufficient-pbkdf2-iterations-happen-in-javascript-and-how-to-fix-it</loc>
<lastmod>2026-09-09T00:41:10.430Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-crafted-zip-file-happens-in-node-js-13165</loc>
<lastmod>2026-09-09T00:39:10.187Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-api-key-exposure-in-request-bodies-happens-in-react</loc>
<lastmod>2026-09-09T00:37:43.740Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-javascript-ast-traversal-and-how-to-fix</loc>
<lastmod>2026-09-08T12:34:57.651Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-origin-validation-bypass-happens-in-express-js-and-how-to-fix</loc>
<lastmod>2026-09-08T09:30:46.073Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-python-sqlalchemy-raw-query-sql-injection-happens-and-how-to-fix</loc>
<lastmod>2026-09-08T09:29:53.981Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-csrf-vulnerabilities-happen-in-node-js-api-clients</loc>
<lastmod>2026-09-08T09:29:04.800Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-python-duckdb-view-creation</loc>
<lastmod>2026-09-07T21:24:31.419Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-php-virtual-filesystem-adapters</loc>
<lastmod>2026-09-07T21:24:09.633Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-api-keys-in-wasm-modules-happen-in-kap</loc>
<lastmod>2026-09-07T21:23:26.672Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sensitive-data-exposure-happens-in-zotero-plugins-and-how-to-fix</loc>
<lastmod>2026-09-07T21:23:07.684Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-user-enumeration-happens-in-django-forms-and-how-to-fix-it</loc>
<lastmod>2026-09-07T09:19:58.809Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-style-template-literal-injection-happens-in-javascript-dom-rendering</loc>
<lastmod>2026-09-07T09:19:44.259Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-arbitrary-code-execution-happens-in-protobufjs-and-how-to-fix-it</loc>
<lastmod>2026-09-07T09:18:52.697Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-php-bulk-email-systems</loc>
<lastmod>2026-09-07T06:09:36.143Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-dependency-update-cooldowns-happen-in-github-dependabot-configurations</loc>
<lastmod>2026-09-07T06:09:05.476Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-api-key-exposure-happens-in-node-js</loc>
<lastmod>2026-09-07T06:07:54.131Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-tensorflow-s-data-service</loc>
<lastmod>2026-09-07T06:04:30.524Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-broken-object-level-authorization-happens-in-express-js</loc>
<lastmod>2026-09-07T06:02:31.104Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-encryption-salts-compromise-credential-storage-in-node-js</loc>
<lastmod>2026-09-07T06:01:55.098Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-prototype-pollution-happens-in-axios</loc>
<lastmod>2026-09-07T06:01:13.295Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unbounded-websocket-message-handling-causes-resource-exhaustion-in-node-js</loc>
<lastmod>2026-09-07T06:00:09.942Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-shell-scripts-and-how-to-fix-it</loc>
<lastmod>2026-09-07T05:59:33.421Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-remote-code-execution-happens-in-handlebars-template-compilation</loc>
<lastmod>2026-09-07T05:57:20.615Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-unbounded-arrays-in-brace-expansion-happens</loc>
<lastmod>2026-09-07T05:55:07.597Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-weak-scrypt-password-hashing-happens-in-node-js</loc>
<lastmod>2026-09-07T05:52:02.582Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-quadratic-complexity-denial-of-service-happens-in-javascript-yaml-parsing</loc>
<lastmod>2026-09-07T05:49:52.261Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-gitlab-bandit-b501-happens-in-python-and-how-to-fix-it</loc>
<lastmod>2026-09-07T05:47:30.605Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-message-corruption-via-protocol-length-header-abuse-happens-in-websocket-implementations</loc>
<lastmod>2026-09-07T05:45:58.636Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-xml-entity-expansion-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-09-07T05:44:35.123Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-trust-prefix-bypass-via-path-traversal-happens-in-python-copier</loc>
<lastmod>2026-09-07T05:42:41.434Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-rate-limiting-enables-denial-of-service-attacks-in-node-js</loc>
<lastmod>2026-09-07T05:41:44.344Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-a-writable-root-filesystem-service-vulnerability-happens-in-docker-compose</loc>
<lastmod>2026-09-07T05:41:12.761Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-zip-bomb-happens-in-node-js</loc>
<lastmod>2026-09-07T05:39:50.968Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-authentication-bypass-happens-in-node-js-websocket-services</loc>
<lastmod>2026-09-07T05:39:02.325Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insufficiently-protected-credentials-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-09-07T05:38:27.735Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-api-authentication-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-09-07T05:36:49.582Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unvalidated-external-data-fetch-happens-in-react-and-how-to-fix</loc>
<lastmod>2026-09-07T05:33:48.035Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cross-site-scripting-happens-in-javascript-parsers-and-how-to-fix</loc>
<lastmod>2026-09-07T05:32:41.091Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-url-parameter-injection-happens-in-javascript-apis-and-how-to-fix</loc>
<lastmod>2026-09-07T05:32:07.203Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sandboxed-iframe-popup-restriction-bypass-happens-in-electron</loc>
<lastmod>2026-09-07T05:31:37.641Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-type-confusion-vulnerabilities-happen-in-javascript-dependencies-and-how-to-fix</loc>
<lastmod>2026-09-07T05:29:59.150Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-oauth-2-0-authorization-code-interception-happens-in-php</loc>
<lastmod>2026-09-07T05:27:46.635Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-oauth-token-binding-prevents-session-hijacking-in-weibo-login-implementation</loc>
<lastmod>2026-09-07T05:27:11.468Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsafe-configuration-storage-happens-in-magento-and-how-to-fix-it</loc>
<lastmod>2026-09-07T05:24:40.907Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dependency-version-pinning-prevents-supply-chain-attacks-in-node-js</loc>
<lastmod>2026-09-07T05:24:00.693Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-java-processbuilder-and-how-to-fix-it</loc>
<lastmod>2026-09-07T05:21:44.590Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-via-template-literals-happens-in-typescript</loc>
<lastmod>2026-09-06T18:27:24.955Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-i18next-fs-backend-and-how-to-fix</loc>
<lastmod>2026-09-06T18:26:50.132Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cross-site-scripting-xss-happens-in-javascript-sanitization-functions</loc>
<lastmod>2026-09-06T18:26:23.633Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-in-basic-ftp-leads-to-file-overwrite-attacks</loc>
<lastmod>2026-09-06T06:22:38.340Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-authentication-on-delete-endpoints-happens-in-python-aiohttp</loc>
<lastmod>2026-09-06T06:21:31.568Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-information-disclosure-vulnerabilities-happen-in-python-apis-and-how-to-fix</loc>
<lastmod>2026-09-05T18:18:48.197Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-vulnerabilities-happen-in-python-subprocess-calls</loc>
<lastmod>2026-09-05T18:16:46.653Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-in-memory-rate-limiting-vulnerabilities-happen-in-node-js-apis</loc>
<lastmod>2026-09-05T06:13:37.808Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-exposed-debug-endpoints-happen-in-express-js-and-how-to-fix</loc>
<lastmod>2026-09-04T18:10:59.942Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-ssrf-happens-in-go-http-handlers</loc>
<lastmod>2026-09-04T18:08:45.844Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-rate-limiting-vulnerabilities-happen-in-node-js-oauth-endpoints</loc>
<lastmod>2026-09-04T06:06:14.037Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unvalidated-external-content-fetching-happens-in-python-build-scripts</loc>
<lastmod>2026-09-04T06:04:51.770Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-attacks-happen-in-php-markdown-parsers</loc>
<lastmod>2026-09-04T06:04:04.666Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-node-js-express-servers</loc>
<lastmod>2026-09-03T18:03:23.574Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-ssrf-via-vulnerable-dependency-versions-happens-in-node-js</loc>
<lastmod>2026-09-03T18:00:42.272Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dependency-confusion-attacks-happen-in-node-js-package-json</loc>
<lastmod>2026-09-03T05:58:15.900Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insecure-credential-storage-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-09-03T05:56:22.387Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-wildcard-dependency-constraints-happen-in-node-js-and-how-to-fix</loc>
<lastmod>2026-09-03T05:55:34.656Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsanitized-language-parameters-happen-in-javascript-and-how-to-fix-them</loc>
<lastmod>2026-09-02T17:51:12.995Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-api-key-exposure-in-url-query-parameters-happens-in-node-js</loc>
<lastmod>2026-09-02T05:48:17.497Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-happens-in-python-fastapi</loc>
<lastmod>2026-09-01T17:45:57.493Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-api-key-exposure-and-unsafe-process-spawning-happens-in-node-js</loc>
<lastmod>2026-09-01T17:44:27.257Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-happens-in-node-js-maintenance-scripts</loc>
<lastmod>2026-09-01T05:13:32.127Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-api-credentials-in-client-side-javascript-happens-in-userscripts</loc>
<lastmod>2026-08-31T17:09:17.990Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-a-vulnerable-websocket-driver-dependency-happens-in-node-js-lockfiles</loc>
<lastmod>2026-08-31T08:44:14.049Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-arbitrary-code-execution-via-command-injection-happens-in-node-js</loc>
<lastmod>2026-08-31T08:38:31.991Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-exponential-time-complexity-causes-denial-of-service-in-brace-expansion</loc>
<lastmod>2026-08-31T08:37:03.118Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-javascript-carousel-libraries-and-how-to-fix</loc>
<lastmod>2026-08-31T08:36:23.340Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unrestricted-file-upload-via-extension-only-validation-happens-in-deno-javascript</loc>
<lastmod>2026-08-31T08:35:41.456Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-dependabot-cooldown-periods-enable-supply-chain-attacks-in-ci-cd</loc>
<lastmod>2026-08-31T08:34:43.938Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-kotlin-android-and-how-to-fix-it</loc>
<lastmod>2026-08-31T08:33:23.444Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-csrf-and-missing-authentication-protection-happens-in-node-js-express-routes</loc>
<lastmod>2026-08-31T08:30:54.881Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insecure-randomness-in-form-data-happens-in-node-js</loc>
<lastmod>2026-08-31T08:30:04.638Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dom-based-cross-site-scripting-happens-in-javascript</loc>
<lastmod>2026-08-31T08:28:38.567Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-inherited-libvips-vulnerabilities-in-sharp-impact-image-processing</loc>
<lastmod>2026-08-31T08:28:03.661Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-infinite-loop-denial-of-service-happens-in-go-s-golang-org</loc>
<lastmod>2026-08-31T08:27:11.299Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-csrf-vulnerabilities-happen-in-express-js-and-how-to-fix-them</loc>
<lastmod>2026-08-31T08:26:11.775Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-node-js-dependencies-and-how-to-fix</loc>
<lastmod>2026-08-31T08:22:34.523Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-javascript-dependency-trees-and-how-to-fix</loc>
<lastmod>2026-08-31T08:20:35.052Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-node-js-decompress-and-how-to-fix</loc>
<lastmod>2026-08-31T08:18:59.961Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-containerd-cri-plugin-command-injection-happens-in-go</loc>
<lastmod>2026-08-31T08:17:49.893Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-vulnerabilities-happen-in-python-file-handling</loc>
<lastmod>2026-08-31T08:16:50.684Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cross-site-request-forgery-csrf-happens-in-express-js</loc>
<lastmod>2026-08-31T08:16:08.305Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-github-actions-mutable-tag-references-and-unsafe-remote-script-execution-enable</loc>
<lastmod>2026-08-31T08:11:34.951Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-javascript-node-js-and-how-to-fix</loc>
<lastmod>2026-08-31T08:09:11.027Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-infinite-loop-dos-happens-in-node-js-id-generation</loc>
<lastmod>2026-08-31T08:06:48.394Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-information-disclosure-and-denial-of-service-vulnerabilities-happen-in-postcss</loc>
<lastmod>2026-08-31T08:06:02.399Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-interpretation-conflict-vulnerability-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-08-31T08:05:15.410Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-invalid-utf-8-input-happens-in-go-12032</loc>
<lastmod>2026-08-31T08:00:18.299Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-node-js-package-managers</loc>
<lastmod>2026-08-31T07:57:19.051Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-authorization-and-code-injection-happen-in-mindustry-javascript-mods</loc>
<lastmod>2026-08-31T07:53:10.499Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-man-in-the-middle-via-ignored-tls-options-happens-in-node</loc>
<lastmod>2026-08-31T07:50:55.780Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-rate-limiting-vulnerabilities-happen-in-fastapi-and-how-to-fix-them</loc>
<lastmod>2026-08-31T05:06:32.834Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unauthenticated-api-exposure-happens-in-node-js-koa-routers</loc>
<lastmod>2026-08-31T05:06:17.869Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-hmac-sha256-keys-compromise-api-authentication-in-harmonyos</loc>
<lastmod>2026-08-31T05:03:55.550Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-api-key-exposure-in-url-parameters-happens-in-python</loc>
<lastmod>2026-08-30T17:02:10.756Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-quadratic-cpu-consumption-in-js-yaml-s-omap-resolution-happens</loc>
<lastmod>2026-08-30T17:01:43.330Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-node-js-migration-scripts</loc>
<lastmod>2026-08-30T17:00:28.166Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-resource-exhaustion-via-missing-fetch-timeouts-happens-in-node-js</loc>
<lastmod>2026-08-30T16:59:52.164Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-invalid-binary-post-requests-happens-in-socket</loc>
<lastmod>2026-08-30T04:59:05.731Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-url-injection-happens-in-node-js-template-literals</loc>
<lastmod>2026-08-30T04:56:46.876Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-file-type-validation-bypass-happens-in-node-js-image-processing</loc>
<lastmod>2026-08-30T04:56:23.048Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-node-js-tmp-package</loc>
<lastmod>2026-08-29T16:52:55.275Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-unbounded-array-expansion-happens-in-javascript</loc>
<lastmod>2026-08-29T16:52:32.318Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsandboxed-plugin-execution-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-08-29T04:48:57.919Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cors-misconfiguration-happens-in-node-js-with-hono</loc>
<lastmod>2026-08-28T16:47:34.404Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-ip-address-parsing-inconsistencies-cause-ssrf-and-trust-boundary-bypass</loc>
<lastmod>2026-08-28T16:47:06.619Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-websocket-protocol-handler-vulnerabilities-happen-in-node-js-dependencies</loc>
<lastmod>2026-08-28T16:46:29.328Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-silent-form-limit-bypasses-happen-in-starlette-and-how-to-fix</loc>
<lastmod>2026-08-28T16:45:11.104Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-ssrf-happens-in-node-js-fetch-tools</loc>
<lastmod>2026-08-28T16:44:49.146Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-ssrf-happens-in-node-js-api-proxies</loc>
<lastmod>2026-08-28T16:43:43.573Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cache-control-header-injection-happens-in-node-js-http-libraries</loc>
<lastmod>2026-08-28T04:41:08.761Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-null-pointer-dereference-from-unchecked-malloc-happens-in-c</loc>
<lastmod>2026-08-28T04:39:51.382Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-and-filename-injection-happens-in-python-file-handling</loc>
<lastmod>2026-08-27T16:38:02.186Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-xml-multiple-root-element-injection-happens-in-node-js</loc>
<lastmod>2026-08-27T04:33:10.706Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-archive-path-traversal-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-08-26T14:52:01.103Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-shell-injection-via-os-system-happens-in-python</loc>
<lastmod>2026-08-26T14:50:41.648Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-node-js-shell-quote-8920</loc>
<lastmod>2026-08-26T14:49:31.170Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dependabot-missing-cooldown-happens-in-github-actions-and-how-to-fix-8940</loc>
<lastmod>2026-08-26T14:48:07.842Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-remote-code-execution-via-security-fix-bypass-happens-in-node-js-8985</loc>
<lastmod>2026-08-26T14:44:00.723Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unauthorized-ssh-command-execution-happens-in-go-and-how-to-fix</loc>
<lastmod>2026-08-26T14:42:34.777Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unauthenticated-proxy-endpoints-enable-dos-amplification-in-fastapi</loc>
<lastmod>2026-08-26T14:38:50.843Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-python-database-scripts-and-how-to-fix</loc>
<lastmod>2026-08-26T14:32:50.674Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-happens-in-browser-extensions</loc>
<lastmod>2026-08-26T14:31:49.911Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-jwt-signature-bypass-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-08-26T14:20:03.258Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unverified-jwt-decoding-happens-in-java-and-how-to-fix-it</loc>
<lastmod>2026-08-26T14:18:53.521Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-arbitrary-file-read-happens-in-python-langsmith-sdk</loc>
<lastmod>2026-08-26T14:17:02.378Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsandboxed-iframe-content-injection-happens-in-javascript-and-how-to-fix</loc>
<lastmod>2026-08-26T14:15:47.562Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsanitized-external-content-injection-happens-in-javascript-and-how-to-fix</loc>
<lastmod>2026-08-26T14:14:35.281Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unbounded-json-body-parsing-happens-in-cloudflare-workers</loc>
<lastmod>2026-08-26T14:10:50.288Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsafe-attribute-injection-happens-in-javascript-i18n-and-how-to-fix</loc>
<lastmod>2026-08-26T14:09:31.758Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-api-keys-happen-in-toml-configuration-files</loc>
<lastmod>2026-08-26T14:08:18.329Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-exponential-complexity-happens-in-javascript</loc>
<lastmod>2026-08-26T14:07:03.813Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dom-based-xss-happens-in-javascript-css-selectors</loc>
<lastmod>2026-08-26T14:05:44.921Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-python-popclip-extensions-and-how-to-fix</loc>
<lastmod>2026-08-26T14:04:29.170Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dependabot-missing-cooldown-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-08-26T14:01:54.534Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unauthenticated-http-endpoints-happen-in-node-js-ecp-servers</loc>
<lastmod>2026-08-26T14:00:53.233Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cross-site-scripting-xss-happens-in-javascript-browser-extensions</loc>
<lastmod>2026-08-26T13:59:27.879Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-node-js-agents-and-how-to-fix</loc>
<lastmod>2026-08-26T13:58:01.405Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-template-injection-happens-in-node-js-ejs-9441</loc>
<lastmod>2026-08-26T13:56:51.109Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-plaintext-secret-storage-happens-in-cloudflare-workers-wrangler-toml</loc>
<lastmod>2026-08-26T13:52:52.692Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-node-js-sqlite-cli-calls</loc>
<lastmod>2026-08-26T13:47:47.185Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-rust-generated-python-scripts</loc>
<lastmod>2026-08-26T13:45:24.037Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-xss-via-incomplete-html-escaping-happens-in-javascript-browser-extensions</loc>
<lastmod>2026-08-26T13:44:05.498Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-authentication-middleware-happens-in-node-js-apis</loc>
<lastmod>2026-08-26T13:38:57.205Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-child-process-command-injection-happens-in-node-js-typescript</loc>
<lastmod>2026-08-26T13:36:26.415Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-via-strcpy-happens-in-c-xml-parsers</loc>
<lastmod>2026-08-26T13:35:07.892Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-python-shell-scripts-and-how-to-fix</loc>
<lastmod>2026-08-26T13:28:36.588Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-javascript-via-defu-and-how-to-fix</loc>
<lastmod>2026-08-26T13:27:18.866Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-oauth-csrf-attacks-happen-in-node-js-and-how-to-fix</loc>
<lastmod>2026-08-26T13:25:55.086Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-reflected-xss-happens-in-astro-and-how-to-fix-it</loc>
<lastmod>2026-08-26T13:24:45.073Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-javascript-i18n-loaders-and-how-to-fix</loc>
<lastmod>2026-08-26T13:22:17.385Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-python-sqlite-utilities-and-how-to-fix</loc>
<lastmod>2026-08-26T13:21:13.771Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-eval-code-injection-happens-in-javascript-and-how-to-fix-it</loc>
<lastmod>2026-08-26T13:19:52.474Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-api-keys-happen-in-javascript-and-how-to-fix-it</loc>
<lastmod>2026-08-26T13:17:30.955Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-plaintext-credential-storage-happens-in-node-js-config-files</loc>
<lastmod>2026-08-26T13:16:17.524Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-csrf-protection-failures-happen-in-fastapi-and-how-to-fix-them</loc>
<lastmod>2026-08-26T13:15:14.049Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsafe-eval-in-javascript-happens-in-react-components</loc>
<lastmod>2026-08-26T13:14:05.200Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-node-js-route-handlers</loc>
<lastmod>2026-08-26T13:09:25.042Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsafe-deserialization-into-interface-happens-in-go-and-how-to-fix</loc>
<lastmod>2026-08-26T13:05:28.042Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-node-js-and-how-to-fix-it</loc>
<lastmod>2026-08-26T13:04:16.642Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-node-js-protobufjs-and-how-to-fix</loc>
<lastmod>2026-08-26T13:01:14.099Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsanitized-ipc-data-injection-happens-in-electron-html</loc>
<lastmod>2026-08-26T12:58:36.046Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-plaintext-token-storage-happens-in-typescript-tauri-and-how-to-fix</loc>
<lastmod>2026-08-26T12:57:24.884Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unrestricted-file-upload-happens-in-node-js-express</loc>
<lastmod>2026-08-26T12:56:09.148Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prompt-injection-happens-in-node-js-llm-integrations</loc>
<lastmod>2026-08-26T12:47:15.879Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsafe-eval-in-browser-chrome-context-happens-in-javascript</loc>
<lastmod>2026-08-26T12:46:10.580Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-an-infinite-loop-vulnerability-happens-in-go-s-text-normalization</loc>
<lastmod>2026-08-26T12:44:44.001Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-weak-randomness-happens-in-node-js-ws-security</loc>
<lastmod>2026-08-26T12:43:31.347Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-vitest-ui-server-and-how-to-fix</loc>
<lastmod>2026-08-26T12:42:13.303Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-innerhtml-xss-happens-in-javascript-browser-extensions-and-how-to-fix</loc>
<lastmod>2026-08-26T12:40:53.377Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-local-file-inclusion-path-traversal-happens-in-javascript-pdf-generation</loc>
<lastmod>2026-08-26T12:38:33.163Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-oauth-2-0-csrf-happens-in-php-and-how-to-fix</loc>
<lastmod>2026-08-26T12:37:21.360Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-authorization-bypass-and-balance-corruption-happen-in-node-js</loc>
<lastmod>2026-08-26T12:33:48.292Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-happens-in-node-js-dependency-trees</loc>
<lastmod>2026-08-26T12:31:15.517Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-inherited-dependency-vulnerabilities-happen-in-node-js-and-how-to-fix</loc>
<lastmod>2026-08-26T12:25:50.089Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-node-js-child-process-calls-10230</loc>
<lastmod>2026-08-26T12:23:04.747Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-heap-buffer-overflows-happen-in-c-zip-extraction</loc>
<lastmod>2026-08-26T12:19:19.650Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-shell-scripts-and-how-to-fix-it</loc>
<lastmod>2026-08-26T12:16:34.059Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-implicit-tls-certificate-verification-happens-in-python-and-how-to-fix</loc>
<lastmod>2026-08-26T12:14:08.177Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cross-site-scripting-happens-in-fast-xml-parser</loc>
<lastmod>2026-08-26T12:12:17.308Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-integer-overflow-happens-in-c-image-processing-and-how-to-fix</loc>
<lastmod>2026-08-26T12:07:41.893Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-arbitrary-file-read-via-sourcemappingurl-happens-in-postcss</loc>
<lastmod>2026-08-26T12:06:23.968Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insecure-update-manifest-fetching-happens-in-node-js</loc>
<lastmod>2026-08-26T12:02:27.413Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-brace-expansion-happens-in-javascript</loc>
<lastmod>2026-08-26T11:59:52.261Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsafe-fall-through-in-getwhereconditions-happens-in-sequelize</loc>
<lastmod>2026-08-26T11:58:21.167Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-postcss-source-map-auto-loading</loc>
<lastmod>2026-08-26T11:55:39.732Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-authentication-happens-in-express-js-apis-and-how-to-fix</loc>
<lastmod>2026-08-26T11:46:32.057Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-open-redirect-via-unvalidated-url-input-happens-in-weex</loc>
<lastmod>2026-08-26T11:42:45.698Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-pnpm-trust-policy-and-release-age-settings-happen-in-node</loc>
<lastmod>2026-08-26T11:38:34.089Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-curl-pipe-shell-happens-in-github-actions-and-how-to-fix</loc>
<lastmod>2026-08-26T11:34:28.571Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-node-js-cli-tools</loc>
<lastmod>2026-08-26T11:31:42.528Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unauthenticated-https-fetch-calls-happen-in-javascript-and-how-to-fix</loc>
<lastmod>2026-08-26T11:30:24.394Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-node-js-temporary-file-creation</loc>
<lastmod>2026-08-26T11:29:13.380Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-stack-buffer-overflows-happen-in-c-with-sprintf</loc>
<lastmod>2026-08-26T11:26:52.424Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-http-transport-hijacking-via-prototype-pollution-happens-in-javascript</loc>
<lastmod>2026-08-26T11:25:44.525Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-node-js-ftp-clients</loc>
<lastmod>2026-08-26T11:24:14.589Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-unbounded-intermediate-arrays-happens-in-javascript</loc>
<lastmod>2026-08-26T11:21:41.818Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-node-js-git-automation</loc>
<lastmod>2026-08-26T11:20:17.962Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-wildcard-postmessage-origins-happen-in-chrome-extensions-and-how-to-fix</loc>
<lastmod>2026-08-26T11:15:34.769Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-specific-input-sequence-happens-in-javascript-marked</loc>
<lastmod>2026-08-26T11:13:14.050Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unvalidated-update-urls-happen-in-node-js-agent-updaters</loc>
<lastmod>2026-08-26T11:09:09.547Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-unbounded-data-happens-in-javascript</loc>
<lastmod>2026-08-26T11:07:51.933Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-crafted-email-headers-happens-in-node-js</loc>
<lastmod>2026-08-26T11:06:34.065Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-catastrophic-backtracking-happens-in-node-js</loc>
<lastmod>2026-08-26T10:59:52.509Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-adjacent-inline-attribute-blocks-happens-in-php</loc>
<lastmod>2026-08-26T10:51:19.335Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-invalid-utf-8-input-happens-in-go</loc>
<lastmod>2026-08-26T10:49:51.779Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unicode-homoglyph-email-bypass-happens-in-next-js-auth-js</loc>
<lastmod>2026-08-26T10:48:31.047Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cross-site-scripting-happens-in-jspdf-and-how-to-fix-it</loc>
<lastmod>2026-08-26T10:41:44.261Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-information-disclosure-happens-in-go-dependency-management-and-how-to-fix</loc>
<lastmod>2026-08-26T10:40:30.891Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-el-injection-happens-in-java-jsf-applications-and-how-to-fix</loc>
<lastmod>2026-08-26T10:37:45.666Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-xml-external-entity-xxe-injection-happens-in-python-11802</loc>
<lastmod>2026-09-24T04:53:27.699Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-malformed-json-input-happens-in-go</loc>
<lastmod>2026-08-26T10:33:45.149Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dependency-chain-forgery-happens-in-go-modules-and-how-to-fix</loc>
<lastmod>2026-08-26T10:28:22.809Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-node-js-async-libraries</loc>
<lastmod>2026-08-26T09:58:15.383Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-python-bigquery-connectors-and-how-to-fix</loc>
<lastmod>2026-08-26T08:35:58.582Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-security-policy-bypass-via-improper-unicode-hostname-canonicalization-happens-in-node</loc>
<lastmod>2026-08-26T03:34:45.740Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsafe-random-number-generation-in-form-data-compromises-multipart-form-security</loc>
<lastmod>2026-08-25T21:08:25.325Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cross-site-scripting-happens-in-xml-parsing-libraries</loc>
<lastmod>2026-08-25T21:08:21.454Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-arbitrary-code-execution-via-protobuf-definition-injection-happens-in-node-js</loc>
<lastmod>2026-08-25T21:07:46.383Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-redos-happens-in-node-js-path-to-regexp</loc>
<lastmod>2026-08-25T07:49:19.644Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-crafted-long-path-tar-archives-happens</loc>
<lastmod>2026-08-25T07:48:50.474Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-credentials-happen-in-node-js-express-routes</loc>
<lastmod>2026-08-25T07:47:17.343Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-trailofbits-python-pickles-in-pytorch-pickles-in-pytorch-happens-in-python</loc>
<lastmod>2026-08-25T07:46:55.918Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-via-unescaped-line-terminators-happens-in-node-js-12008</loc>
<lastmod>2026-08-24T21:21:55.330Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-express-check-csurf-middleware-usage-happens-in-javascript-express</loc>
<lastmod>2026-08-24T09:18:27.025Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-unbounded-brace-expansion-happens-in-node-js-11871</loc>
<lastmod>2026-08-24T02:08:43.045Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-information-disclosure-and-dos-via-malformed-cache-control-directives-happens</loc>
<lastmod>2026-08-23T22:21:14.043Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-react-router-ssr-xss-in-scrollrestoration-happens-and-how-to-fix</loc>
<lastmod>2026-08-23T22:20:01.752Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-route-guard-bypass-via-path-traversal-happens-in-fastify</loc>
<lastmod>2026-08-23T22:18:54.926Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-via-unescaped-line-terminators-happens-in-node-js-11884</loc>
<lastmod>2026-08-23T08:21:19.278Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insecure-string-copy-functions-happen-in-c-and-how-to-fix</loc>
<lastmod>2026-08-22T20:19:42.775Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-distributed-lock-takeover-happens-in-node-js-and-how-to-fix</loc>
<lastmod>2026-08-22T20:19:35.415Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-infinite-loop-happens-in-javascript-nanoid</loc>
<lastmod>2026-08-22T20:17:51.667Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-php-and-how-to-fix-it</loc>
<lastmod>2026-08-22T20:16:08.416Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-c-lang-security-use-after-free-use-after-free-happens</loc>
<lastmod>2026-08-22T08:11:33.502Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-unbounded-recursion-happens-in-python-json-parsing</loc>
<lastmod>2026-08-22T08:11:14.939Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cr-lf-injection-happens-in-node-js-http-proxy-middleware</loc>
<lastmod>2026-08-21T20:08:32.758Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-regular-expression-happens-in-node-js-dependencies</loc>
<lastmod>2026-08-21T20:05:47.386Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-privilege-escalation-via-incorrect-user-id-handling-happens-in-go</loc>
<lastmod>2026-08-21T08:04:04.266Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-csrf-bypass-happens-in-react-router-rsc-mode</loc>
<lastmod>2026-08-21T08:03:54.627Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-exponential-complexity-happens-in-node-js</loc>
<lastmod>2026-08-20T20:01:08.095Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-stored-cross-site-scripting-stored-xss-happens-in-javascript-map-components</loc>
<lastmod>2026-08-20T20:00:25.388Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-javascript-lang-security-detect-child-process-detect-child-process-happens-11674</loc>
<lastmod>2026-08-20T19:57:50.667Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-via-child-process-happens-in-node-js-11670</loc>
<lastmod>2026-08-20T19:57:44.232Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dos-via-unbounded-intermediate-arrays-happens-in-javascript-brace-expansion</loc>
<lastmod>2026-08-20T07:55:28.564Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-information-disclosure-via-unstripped-credential-headers-during-http-redirects-happens</loc>
<lastmod>2026-08-20T07:53:55.421Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cache-control-header-parsing-vulnerabilities-happen-in-node-js-http-clients</loc>
<lastmod>2026-08-19T19:52:04.851Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-infinite-loop-happens-in-go-xpath-libraries</loc>
<lastmod>2026-08-19T19:51:49.005Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-aws-credentials-happen-in-node-js-configuration-files</loc>
<lastmod>2026-08-19T19:50:54.896Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-github-actions-mutable-action-tag-happens-in-github-actions-yaml</loc>
<lastmod>2026-08-19T19:50:11.386Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-aws-secret-access-keys-happen-in-configuration-files</loc>
<lastmod>2026-08-19T19:49:18.915Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-proxy-authorization-header-leakage-happens-in-axios-and-how-to-fix</loc>
<lastmod>2026-08-19T19:49:16.681Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-rate-limiting-happens-in-express-js-authentication-endpoints</loc>
<lastmod>2026-08-19T07:46:08.196Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-zip-bomb-happens-in-node-js-adm</loc>
<lastmod>2026-08-18T19:41:53.017Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cors-misconfiguration-happens-in-fastapi-and-how-to-fix-it</loc>
<lastmod>2026-08-18T07:38:21.356Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-proto-key-happens-in-axios</loc>
<lastmod>2026-08-18T07:36:04.501Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-pnpm-trust-policy-misconfiguration-happens-in-node-js</loc>
<lastmod>2026-08-17T07:27:54.368Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dom-based-xss-happens-in-jquery-tagsinput-and-how-to-fix</loc>
<lastmod>2026-08-17T07:27:07.254Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-csrf-vulnerability-happens-in-javascript-fetch-calls-and-how-to-fix</loc>
<lastmod>2026-08-17T07:27:03.479Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-zip-parsing-happens-in-node-js</loc>
<lastmod>2026-08-16T19:23:52.314Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-vulnerabilities-happen-in-node-js-build-scripts</loc>
<lastmod>2026-08-16T19:23:07.034Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-unbounded-intermediate-arrays-happens-in-node-js</loc>
<lastmod>2026-08-16T19:22:57.131Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-weak-bcrypt-salt-rounds-happen-in-node-js</loc>
<lastmod>2026-08-16T19:22:54.980Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-csrf-protection-gaps-happen-in-express-js-applications</loc>
<lastmod>2026-08-16T19:22:34.927Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insufficient-input-validation-happens-in-typescript-and-how-to-fix-it</loc>
<lastmod>2026-08-15T19:18:03.232Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-supply-chain-timing-attacks-happen-in-pnpm-workspaces</loc>
<lastmod>2026-08-15T19:17:06.064Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-node-js-child-process-calls-11268</loc>
<lastmod>2026-08-15T19:15:56.761Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-supply-chain-risk-from-missing-package-age-validation-happens-in-pnpm</loc>
<lastmod>2026-08-15T19:15:26.615Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-vulnerabilities-happen-in-node-js-development-servers</loc>
<lastmod>2026-08-15T19:15:02.460Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-plaintext-credential-storage-happens-in-json-configuration-files</loc>
<lastmod>2026-08-15T07:11:31.488Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-vue-i18n-s-handleflatjson</loc>
<lastmod>2026-08-15T07:11:22.815Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-email-exhaustion-denial-of-service-happens-in-node-js-otp-endpoints</loc>
<lastmod>2026-08-14T19:06:29.290Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unauthenticated-denial-of-service-happens-in-react-router</loc>
<lastmod>2026-08-14T07:04:39.362Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-github-actions-mutable-action-tags-enable-supply-chain-attacks</loc>
<lastmod>2026-08-14T07:03:29.359Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sensitive-data-exposure-in-error-logging-happens-in-typescript-deno</loc>
<lastmod>2026-08-14T07:02:16.470Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-http-header-injection-happens-in-go-and-how-to-fix-it</loc>
<lastmod>2026-08-13T18:58:03.649Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-and-security-policy-bypass-happens-in-node-js-dependencies</loc>
<lastmod>2026-08-12T18:49:13.405Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-uninitialized-memory-vulnerabilities-happen-in-rust-and-how-to-fix-them</loc>
<lastmod>2026-08-12T06:44:47.636Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-arbitrary-http-header-injection-via-prototype-pollution-happens-in-javascript</loc>
<lastmod>2026-08-11T18:42:18.313Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-octal-ip-address-parsing-inconsistency-enables-ssrf-in-node-js</loc>
<lastmod>2026-08-11T06:35:04.858Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cross-site-scripting-xss-happens-in-javascript-template-rendering</loc>
<lastmod>2026-08-10T18:33:39.504Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-infinite-loop-happens-in-node-js-dependencies</loc>
<lastmod>2026-08-10T18:32:59.265Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-infinite-loop-happens-in-go</loc>
<lastmod>2026-08-10T06:30:16.474Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-deeply-nested-field-names-happens-in-node</loc>
<lastmod>2026-08-10T06:29:43.053Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-denial-of-service-happens-in-node-js-http-libraries</loc>
<lastmod>2026-08-10T06:29:29.320Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-php-pdo-queries-and-how-to-fix</loc>
<lastmod>2026-08-10T06:28:53.513Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-binary-attachment-accumulation-causes-denial-of-service-in-python-socketio</loc>
<lastmod>2026-08-10T06:27:40.891Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-broken-authentication-happens-in-node-js-express-apis</loc>
<lastmod>2026-08-09T18:24:36.119Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-crafted-zip-file-happens-in-node-js</loc>
<lastmod>2026-08-09T18:22:52.158Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-quadratic-cpu-consumption-happens-in-javascript-yaml-parsing</loc>
<lastmod>2026-08-09T06:20:22.972Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-unbounded-data-size-happens-in-node-js-10658</loc>
<lastmod>2026-08-09T06:19:51.567Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-shell-injection-in-github-actions-happens-in-yaml-workflows</loc>
<lastmod>2026-08-08T18:15:10.601Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insufficient-password-hashing-cost-factor-happens-in-node-js</loc>
<lastmod>2026-08-08T06:12:53.818Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-arbitrary-code-execution-via-template-imports-happens-in-javascript-lodash</loc>
<lastmod>2026-08-08T06:11:59.984Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-ipv4-mapped-ipv6-addresses-bypass-rate-limiting-in-express-js</loc>
<lastmod>2026-08-07T18:09:28.487Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-remote-memory-exhaustion-happens-in-rust-quic-implementations</loc>
<lastmod>2026-08-07T18:06:49.641Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-ssrf-happens-in-node-js-ip-address</loc>
<lastmod>2026-08-07T18:05:58.161Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sensitive-data-exposure-happens-in-python-web-applications</loc>
<lastmod>2026-08-07T06:04:17.633Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-csv-to-sql-converters</loc>
<lastmod>2026-08-07T05:38:46.403Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-python-subprocess-and-how-to-fix-it-10595</loc>
<lastmod>2026-08-07T05:37:42.669Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-cryptographic-keys-in-javascript-proxy-scripts-get-exposed</loc>
<lastmod>2026-08-07T05:37:37.651Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-happens-in-node-js-cli-tools</loc>
<lastmod>2026-08-06T18:16:18.094Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-resource-leaks-happens-in-go-ssh-libraries</loc>
<lastmod>2026-08-06T18:16:15.398Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-credential-leakage-in-github-actions-happens-in-node-js</loc>
<lastmod>2026-08-06T18:15:34.425Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-authorization-checks-happen-in-node-js-whatsapp-bots</loc>
<lastmod>2026-08-06T18:13:13.521Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unbound-thread-allocation-denial-of-service-happens-in-python-engine-io</loc>
<lastmod>2026-08-06T05:33:08.869Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-message-level-raw-option-bypass-happens-in-node-js-nodemailer</loc>
<lastmod>2026-08-06T05:32:32.625Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-credential-exposure-over-http-happens-in-python-requests</loc>
<lastmod>2026-08-06T05:31:38.615Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insecure-api-key-transmission-happens-in-javascript-browser-extensions</loc>
<lastmod>2026-08-05T20:57:32.658Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-url-injection-via-unvalidated-user-input-happens-in-node-js</loc>
<lastmod>2026-08-05T20:57:02.937Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insecure-https-requests-and-missing-timeouts-happen-in-python</loc>
<lastmod>2026-08-05T20:54:39.782Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cache-control-header-mishandling-happens-in-node-js-http-clients</loc>
<lastmod>2026-08-05T20:52:26.253Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-xml-entity-expansion-denial-of-service-happens-in-node-js</loc>
<lastmod>2026-08-05T05:06:03.634Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-arbitrary-code-execution-via-command-injection-happens-in-node-js-shell</loc>
<lastmod>2026-08-05T05:05:29.260Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-xml-node-injection-happens-in-javascript-xml-parsing</loc>
<lastmod>2026-08-05T02:39:17.930Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-security-bypass-in-salesforce-soql-queries-happens-in-apex</loc>
<lastmod>2026-08-05T02:39:16.757Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-remote-code-execution-via-serialize-javascript-happens-in-node-js</loc>
<lastmod>2026-08-04T08:17:46.061Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unvalidated-url-input-handling-happens-in-sveltekit-with-tauri</loc>
<lastmod>2026-08-04T03:08:15.093Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unicode-normalization-infinite-loops-happen-in-go-and-how-to-fix</loc>
<lastmod>2026-08-04T01:32:02.720Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-rate-limiting-happens-in-next-js-api-routes</loc>
<lastmod>2026-08-04T01:31:36.382Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-node-js-mysql-queries</loc>
<lastmod>2026-08-04T01:30:30.435Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-credential-header-disclosure-happens-in-electron-updater-and-how-to-fix</loc>
<lastmod>2026-08-01T10:36:05.169Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-authentication-checks-happen-in-react-route-handlers</loc>
<lastmod>2026-08-01T06:21:31.165Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-shell-metacharacter-injection-happens-in-node-js-ssh-provisioning</loc>
<lastmod>2026-08-01T06:21:26.124Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-oauth-token-audience-bypass-happens-in-node-js-serverless-functions</loc>
<lastmod>2026-07-31T19:26:35.394Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-xss-via-unescaped-sender-name-happens-in-javascript-chat-widgets</loc>
<lastmod>2026-07-31T19:25:38.037Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-signature-verification-bypass-happens-in-node-js-crypto</loc>
<lastmod>2026-07-31T19:25:04.852Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-insecure-nonce-generation-with-math-random-happens-in-node-js-http</loc>
<lastmod>2026-07-31T19:24:50.419Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-sql-injection-happens-in-php-mysqli-and-how-to-fix-it</loc>
<lastmod>2026-07-31T06:53:44.981Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-authorization-enforcement-happens-in-node-js-express-routers</loc>
<lastmod>2026-07-31T05:43:13.376Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-algolia-api-key-exposure-happens-in-ejs-templates</loc>
<lastmod>2026-07-31T03:50:41.640Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unauthenticated-endpoint-exposure-happens-in-node-js-express</loc>
<lastmod>2026-07-31T03:50:28.446Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsigned-auto-update-code-execution-happens-in-node-js-neutralinojs</loc>
<lastmod>2026-07-31T03:49:47.129Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-via-shell-metacharacter-escaping-happens-in-node-js</loc>
<lastmod>2026-07-31T03:49:45.881Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-malformed-http-header-decoding-happens-in-node</loc>
<lastmod>2026-07-30T08:54:31.263Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-supply-chain-trust-policy-bypass-happens-in-node-js-pnpm-workspaces</loc>
<lastmod>2026-07-30T08:52:31.601Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-api-keys-happen-in-node-js-client-side-javascript</loc>
<lastmod>2026-07-30T04:49:08.348Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unauthenticated-api-access-happens-in-node-js-express-endpoints</loc>
<lastmod>2026-07-29T18:01:56.002Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unbounded-brace-expansion-dos-happens-in-node-js</loc>
<lastmod>2026-07-29T18:01:31.484Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-session-fixation-happens-in-php-oauth-login-handlers</loc>
<lastmod>2026-07-29T05:56:52.652Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-happens-in-node-js-http-clients</loc>
<lastmod>2026-07-29T05:56:20.380Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsafe-eval-code-execution-happens-in-javascript-game-scripting</loc>
<lastmod>2026-07-28T17:53:25.996Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-api-key-exposure-happens-in-javascript-and-how-to-fix</loc>
<lastmod>2026-07-28T17:50:38.235Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-broken-access-control-via-supply-chain-dependency-poisoning-happens-in-typo3</loc>
<lastmod>2026-07-28T17:50:25.416Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-via-execsync-happens-in-node-js-cli-tools</loc>
<lastmod>2026-07-28T09:06:00.170Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-in-intel-sgx-enclave-ecalls-happens-in-c</loc>
<lastmod>2026-07-27T21:01:00.755Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-happens-in-node-js-server-js</loc>
<lastmod>2026-07-27T21:00:14.152Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-api-key-exposure-in-client-side-html-happens-in-javascript-web</loc>
<lastmod>2026-07-27T20:58:40.032Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-html-sanitizer-bypass-via-xmp-tag-passthrough-happens-in-node-js</loc>
<lastmod>2026-07-27T08:57:02.875Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-minimum-release-age-happens-in-pnpm-workspaces</loc>
<lastmod>2026-07-27T08:55:06.657Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-weak-pbkdf2-key-derivation-happens-in-frida-android-server</loc>
<lastmod>2026-07-26T20:49:51.424Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-gzip-bomb-happens-in-node-js-tar</loc>
<lastmod>2026-07-26T08:48:04.745Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-malformed-http-header-decoding-happens-in-opentelemetry</loc>
<lastmod>2026-07-26T08:46:42.515Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-remote-code-execution-happens-in-node-js-remote-run-js</loc>
<lastmod>2026-07-26T08:45:35.576Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-happens-in-c-sgx-enclave-memcpy</loc>
<lastmod>2026-07-26T08:45:23.646Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-redos-happens-in-node-js-mcp-sdk-and-how-to-fix</loc>
<lastmod>2026-07-25T20:43:17.535Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-secrets-inherit-over-privilege-happens-in-github-actions-reusable-workflows</loc>
<lastmod>2026-07-25T08:37:35.422Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-integer-underflow-in-array-splice-operations-happens-in-c</loc>
<lastmod>2026-07-25T08:36:27.069Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-ssrf-happens-in-javascript-fetch</loc>
<lastmod>2026-07-25T08:35:55.339Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-no-proxy-bypass-via-crafted-url-happens-in-node-js-axios-9226</loc>
<lastmod>2026-07-24T20:34:21.719Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-server-side-request-forgery-happens-in-node-js-httpproxy-js</loc>
<lastmod>2026-07-24T20:33:14.188Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dns-rebinding-attacks-happen-in-node-js-mcp</loc>
<lastmod>2026-07-24T20:33:04.393Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-shell-injection-via-variable-interpolation-happens-in-github-actions</loc>
<lastmod>2026-07-24T20:31:47.185Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-ruby-backticks-and-how-to-fix-it</loc>
<lastmod>2026-07-24T20:30:14.180Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-via-sprintf-happens-in-c-string-formatting</loc>
<lastmod>2026-07-23T20:25:28.844Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-supply-chain-code-injection-happens-in-node-js-build-scripts</loc>
<lastmod>2026-07-23T20:24:24.310Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-middleware-proxy-bypass-happens-in-next-js-app-router-with-turbopack</loc>
<lastmod>2026-07-23T20:22:38.953Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-arbitrary-code-execution-via-injected-protobuf-definition-type-fields-happens</loc>
<lastmod>2026-07-23T08:17:26.949Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unsafe-pickle-deserialization-happens-in-numpy-s-np-load</loc>
<lastmod>2026-07-23T07:20:55.867Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-ssrf-and-credential-leakage-via-absolute-urls-happens-in-axios</loc>
<lastmod>2026-07-23T07:20:30.485Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-client-side-denial-of-service-happens-in-node-js-ftp-clients</loc>
<lastmod>2026-07-22T19:17:47.821Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-pickle-based-arbitrary-code-execution-happens-in-pytorch</loc>
<lastmod>2026-07-22T19:17:14.023Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-websocket-protocol-length-header-abuse-happens-in-node-js</loc>
<lastmod>2026-07-22T19:16:13.096Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-quadratic-complexity-dos-via-mailto-validator-happens-in-linkify-it</loc>
<lastmod>2026-07-22T19:14:29.534Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dom-based-xss-via-jquery-html-happens-in-javascript</loc>
<lastmod>2026-07-22T07:12:27.299Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-hardcoded-aws-access-key-id-exposure-happens-in-yaml-template-files</loc>
<lastmod>2026-07-22T07:12:05.743Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-unvalidated-put-value-records-happen-in-node-js-libp2p-kad-dht</loc>
<lastmod>2026-07-22T07:11:18.504Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-exponential-time-complexity-denial-of-service-happens-in-brace-expansion</loc>
<lastmod>2026-07-22T07:11:12.359Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-via-excessive-memory-allocation-happens-in-node-js</loc>
<lastmod>2026-07-22T07:09:49.484Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-predictable-key-material-generation-happens-in-node-js-pbkdf2</loc>
<lastmod>2026-07-21T16:08:15.633Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-happens-in-c-html-parsing-and-how-to-fix</loc>
<lastmod>2026-07-12T23:56:33.728Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-memory-exhaustion-via-large-comma-separated-selector-lists-happens-in-python-8773</loc>
<lastmod>2026-07-12T11:54:42.724Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-prototype-pollution-via-proto-key-happens-in-node-js-defu</loc>
<lastmod>2026-07-12T11:54:16.918Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-in-memcpy-happens-in-node-js-n-api-bindings</loc>
<lastmod>2026-07-12T11:54:05.764Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-in-locale-name-processing-happens-in-c</loc>
<lastmod>2026-07-11T11:46:36.405Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-ssh-channel-exhaustion-happens-in-go-crypto-and-how-to-fix</loc>
<lastmod>2026-07-11T04:13:28.660Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-api-key-exposure-in-configuration-files-happens-in-toml-config</loc>
<lastmod>2026-07-10T11:39:47.537Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-integer-overflow-in-buffer-size-calculation-happens-in-c-and-how-8627</loc>
<lastmod>2026-07-10T11:38:29.828Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-happens-in-ruby-yard-server-and-how-to-fix</loc>
<lastmod>2026-07-09T23:31:45.507Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-authentication-bypass-happens-in-pyjwt-and-how-to-fix-it</loc>
<lastmod>2026-07-07T11:09:40.594Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-in-stb-image-h-memcpy-happens-in-c-image</loc>
<lastmod>2026-07-06T10:58:05.197Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-in-fgets-happens-in-c-and-how-to-fix</loc>
<lastmod>2026-07-06T10:58:02.818Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-argument-injection-happens-in-node-js-copilot-tool-bridge</loc>
<lastmod>2026-07-04T22:48:14.844Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-python-os-popen-and-how-to-fix</loc>
<lastmod>2026-07-04T10:43:41.649Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-cors-credential-reflection-happens-in-hono-middleware-and-how-to-fix</loc>
<lastmod>2026-06-29T16:14:32.826Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-in-handle-interlink-event-happens-in-c-terminal-event</loc>
<lastmod>2026-06-29T00:58:21.802Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-integer-overflow-in-js-realloc-array-happens-in-c-quickjs</loc>
<lastmod>2026-06-28T12:52:58.407Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-in-strcat-happens-in-c-and-how-to-fix</loc>
<lastmod>2026-06-27T07:59:36.025Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-happens-in-c-memstream-h-and-how-to-fix</loc>
<lastmod>2026-06-25T02:08:03.263Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-happens-in-node-js-devalue</loc>
<lastmod>2026-06-25T02:07:27.631Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-improper-handling-of-case-sensitivity-happens-in-go-mcp-sdk</loc>
<lastmod>2026-06-24T05:10:46.317Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-via-sprintf-happens-in-c-fuzzer-code</loc>
<lastmod>2026-06-23T13:37:33.243Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-form-limit-bypass-dos-happens-in-python-starlette</loc>
<lastmod>2026-06-22T09:14:19.273Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-happens-in-c-rtspsession-h-and-how-to-fix</loc>
<lastmod>2026-06-22T09:09:33.481Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-heap-buffer-overflow-happens-in-c-memcpy-with-untrusted-pdu-length</loc>
<lastmod>2026-06-19T06:46:37.516Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-integer-overflow-in-malloc-happens-in-c-emulator-memory-allocation</loc>
<lastmod>2026-06-19T01:15:25.881Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-strcpy-buffer-overflow-happens-in-c-debugger-command-handling</loc>
<lastmod>2026-06-18T11:00:46.862Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-in-sms-response-buffer-handling-happens-in-c</loc>
<lastmod>2026-06-18T01:52:47.470Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-kernel-stack-buffer-overflow-happens-in-c-vsprintf</loc>
<lastmod>2026-06-18T01:50:03.850Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-reflected-xss-happens-in-jinja2-template-rendering-and-how-to-fix</loc>
<lastmod>2026-06-15T17:08:04.049Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-happens-in-c-imagemagick-drawing-wand</loc>
<lastmod>2026-06-15T17:06:16.489Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-heap-buffer-overflow-happens-in-c-wifi-frame-capture</loc>
<lastmod>2026-06-15T08:33:21.337Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-happens-in-c-filesystem-header-parsing</loc>
<lastmod>2026-06-14T16:51:19.195Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-ldap-injection-happens-in-c-with-openldap-and-how-to-fix</loc>
<lastmod>2026-06-14T01:24:56.436Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-lua-openwrt-rpc-handlers</loc>
<lastmod>2026-06-14T01:23:50.351Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-integer-overflow-in-path-join-happens-in-c</loc>
<lastmod>2026-06-11T10:12:59.325Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-a-named-pipe-i-o-race-condition-happens-in-rust-mio</loc>
<lastmod>2026-06-10T23:15:24.132Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-denial-of-service-in-ssh-key-exchange-happens-in-go-golang</loc>
<lastmod>2026-06-10T10:47:07.508Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-dos-via-sparse-array-deserialization-happens-in-svelte-devalue</loc>
<lastmod>2026-06-09T23:00:52.331Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-heap-buffer-overflow-via-strcpy-happens-in-c-frei0r-plugins</loc>
<lastmod>2026-06-09T10:57:31.649Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-heap-buffer-overflow-happens-in-c-kconfig-symbol-c</loc>
<lastmod>2026-06-09T04:59:56.979Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-happens-in-c-bluetooth-device-handling</loc>
<lastmod>2026-06-07T16:57:58.888Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-ldap-injection-happens-in-python-apache-airflow-fab-security-manager</loc>
<lastmod>2026-06-06T02:15:09.715Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-command-injection-happens-in-java-runtimeexec-and-how-to-fix-it</loc>
<lastmod>2026-06-06T02:14:10.125Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-path-traversal-in-open-happens-in-python-and-how-to-fix</loc>
<lastmod>2026-06-06T02:12:48.506Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-happens-in-c-patchesc-sprintf-macros</loc>
<lastmod>2026-06-06T02:12:16.345Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-integer-overflow-in-tls-kdf-buffer-allocation-happens-in-c</loc>
<lastmod>2026-06-06T02:11:47.131Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-buffer-overflow-in-modxoqueuec-memcpy-happens-in-c-embedded-systems</loc>
<lastmod>2026-06-06T02:08:24.937Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-heap-buffer-overflow-happens-in-c-jpeg2000-decoding</loc>
<lastmod>2026-06-05T16:41:21.257Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/shell-injection-in-mkmultidtbpy-how-string-concatenation</loc>
<lastmod>2026-06-02T08:42:14.614Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/buffer-over-read-in-sslsniffc-findlibrarypath-when-strlen</loc>
<lastmod>2026-06-03T09:52:13.264Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/axios-dos-via-unbounded-stream-consumption-fixed</loc>
<lastmod>2026-06-03T08:00:20.124Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/cve-2025-14874-nodemailer-dos-via-crafted-email</loc>
<lastmod>2026-06-03T08:31:40.037Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/locking-down-docker-preventing-privilege-escalation-in-container</loc>
<lastmod>2026-06-03T10:12:17.892Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/mass-assignment-vulnerability-why-your-rails-models-need</loc>
<lastmod>2026-06-03T10:00:18.637Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-buffer-overflow-in-ble-midi</loc>
<lastmod>2026-06-03T10:01:12.763Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/thread-safe-tokenization-fixing-strtok-reentrancy-in-game</loc>
<lastmod>2026-06-03T10:01:44.122Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-overflow-in-toml-parser-how-integer-overflow</loc>
<lastmod>2026-06-03T10:16:41.644Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-corruption-via-unchecked-memcpy-how-integer-overflow</loc>
<lastmod>2026-06-03T10:02:31.745Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/integer-overflow-to-heap-buffer-overflow-fixing</loc>
<lastmod>2026-06-03T10:01:44.410Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/use-after-free-in-zmaph-how-a-missing</loc>
<lastmod>2026-06-03T10:15:54.923Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/shell-injection-via-ossystem-how-a-single-line</loc>
<lastmod>2026-06-03T09:50:48.820Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/buffer-overflow-in-rs-232-serial-input</loc>
<lastmod>2026-06-03T10:01:50.809Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-buffer-overflow-fixed-memcpy-without-bounds-checking</loc>
<lastmod>2026-06-03T10:16:15.460Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/kernel-memory-corruption-via-ebpf-buffer-overflow</loc>
<lastmod>2026-06-03T10:02:16.451Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/cve-2026-40073-how-a-bodysizelimit-bypass</loc>
<lastmod>2026-06-03T10:03:02.281Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/buffer-overflow-in-meshtastic-how-one-missing-bounds</loc>
<lastmod>2026-06-03T09:36:05.268Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/integer-overflow-to-heap-corruption-fixing-a-critical-5601</loc>
<lastmod>2026-06-03T08:21:21.985Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-buffer-overflow-in-stbimageh-how-a-missing</loc>
<lastmod>2026-06-03T10:03:32.659Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/go-jose-dos-vulnerability-fixing-jwe-object-exploitation</loc>
<lastmod>2026-06-03T08:13:10.009Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/wildcard-postmessage-origins-when-your-bridge-becomes</loc>
<lastmod>2026-06-03T09:58:52.371Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/sql-injection-via-string-formatting-how-parameterized-queries</loc>
<lastmod>2026-06-03T09:30:47.337Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/from-texttemplate-to-htmltemplate-closing-the-xss-door</loc>
<lastmod>2026-06-03T08:23:52.505Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-buffer-overflow-in-libcurl-callback</loc>
<lastmod>2026-06-03T09:54:52.256Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-buffer-overflow-fixed-sprintf-to-snprintf</loc>
<lastmod>2026-06-03T08:17:10.457Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-buffer-overflow-in-elf-parser-how-a-missing-bounds-check-almost-became-a-heap-exploit</loc>
<lastmod>2026-06-03T10:14:01.241Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/buffer-overflow-in-c-how-unsafe-strcpy-almost-broke-everything</loc>
<lastmod>2026-06-03T09:50:20.581Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/shell-injection-via-unsafe-string-concatenation-in-grpcurl-command-generation</loc>
<lastmod>2026-06-03T10:17:10.229Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/integer-overflow-to-heap-buffer-overflow-a-critical-cve-in-opencv-image-processing</loc>
<lastmod>2026-06-03T10:06:37.528Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/redos-in-nushells-tui-when-search-input-freezes-your-terminal</loc>
<lastmod>2026-06-03T10:03:28.067Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/buffer-overflow-in-minizh-how-a-missing-length-check-could-lead-to-privilege-escalation</loc>
<lastmod>2026-06-03T08:22:38.287Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/path-traversal-in-tftp-server-how-directory-traversal-bugs-enable-arbitrary-file-writes</loc>
<lastmod>2026-06-03T10:06:40.274Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-buffer-overflow-in-nanosvg-how-a-crafted-svg-file-could-lead-to-code-execution</loc>
<lastmod>2026-06-03T10:06:53.565Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/integer-overflow-in-graphics-blit-when-bit-shifts-go-dangerously-wrong</loc>
<lastmod>2026-06-03T10:02:06.902Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/toctou-symlink-attack-fixed-how-race-conditions-threaten-lock-files</loc>
<lastmod>2026-06-03T10:01:23.860Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/integer-overflow-in-rust-how-unchecked-addition-can-bypass-file-size-limits</loc>
<lastmod>2026-06-03T09:38:32.447Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-overflow-in-libfaac-filtbankc-when-audio-metadata-becomes-a-weapon</loc>
<lastmod>2026-06-03T10:26:26.581Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-buffer-overflow-in-midi-file-parsing-how-a-crafted-file-can-corrupt-memory</loc>
<lastmod>2026-06-03T10:17:30.394Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/hardcoded-api-keys-in-init-scripts-a-silent-security-disaster</loc>
<lastmod>2026-06-03T10:13:31.732Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/buffer-overflow-via-strcpy-how-unsafe-string-copies-crash-programs-and-compromise-security</loc>
<lastmod>2026-06-03T10:17:31.247Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-buffer-overflow-in-c-speech-processing-how-a-missing-bounds-check-almost-became-a-critical-expl</loc>
<lastmod>2026-06-03T10:05:38.006Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/sandboxie-kernel-hook-flaw-when-sandboxes-let-keystrokes-escape</loc>
<lastmod>2026-06-03T10:04:54.118Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/code-injection-via-eval-how-a-critical-python-flaw-was-fixed</loc>
<lastmod>2026-06-03T10:27:10.682Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-buffer-overflow-in-c-how-strcpy-without-bounds-checking-opens-the-door-to-exploitation</loc>
<lastmod>2026-06-03T10:27:39.284Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/integer-overflow-in-malloc-how-a-silent-bug-becomes-a-heap-overflow</loc>
<lastmod>2026-06-03T10:06:05.031Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/command-injection-in-privileged-nginx-scripts-a-high-severity-fix</loc>
<lastmod>2026-06-03T10:18:46.918Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/stack-overflow-in-c-how-strcpy-and-strcat-put-games-at-risk</loc>
<lastmod>2026-06-03T10:26:53.984Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/unsafe-dict-merge-in-scapy-how-dictupdate-opens-the-door-to-object-injection</loc>
<lastmod>2026-06-03T10:06:44.337Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-buffer-overflows-in-yaml-parser-how-unchecked-memcpy-calls-create-critical-attack-vectors</loc>
<lastmod>2026-06-03T10:08:33.559Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/how-missing-checksum-validation-opens-the-door-to-supply-chain-attacks</loc>
<lastmod>2026-06-03T10:10:03.467Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-buffer-overflow-in-crsf-firmware-how-one-missing-check-could-crash-a-drone</loc>
<lastmod>2026-06-03T10:06:35.951Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/stack-buffer-overflow-in-amigaos-c-code-how-strcpy-almost-became-a-backdoor</loc>
<lastmod>2026-06-03T10:05:55.573Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-buffer-overflow-in-opencstlh-how-unchecked-memcpy-kills-security</loc>
<lastmod>2026-06-03T10:07:12.104Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/shell-injection-via-ossystem-how-unsanitized-input-becomes-a-command-execution-nightmare</loc>
<lastmod>2026-06-03T10:07:51.666Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-buffer-overflow-in-cachec-how-unsigned-integer-underflow-opens-the-door-to-remote-code-exec</loc>
<lastmod>2026-06-03T10:08:41.104Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/shell-script-json-injection-when-printf-becomes-a-security-risk</loc>
<lastmod>2026-06-03T10:11:56.320Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/command-injection-via-shelltrue-how-one-flag-opens-the-door-to-os-takeover</loc>
<lastmod>2026-06-03T10:07:55.038Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/heap-buffer-overflow-in-meltedforge-array-insert-critical-fix</loc>
<lastmod>2026-06-03T10:08:32.878Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/use-after-free-in-windows-icmp-processing-a-race-to-heap-corruption</loc>
<lastmod>2026-06-03T10:12:06.453Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-rce-in-handlebarsjs-how-cve-2026-33937-was-fixed</loc>
<lastmod>2026-09-20T16:21:48.280Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/slidev-resolver-vulnerability-when-themes-become-trojan-horses</loc>
<lastmod>2026-06-03T09:43:19.250Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-file-upload-vulnerability-fixed-how-unrestricted-uploads-put-flask-apis-at-risk</loc>
<lastmod>2026-06-03T10:09:54.565Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/double-free-heap-corruption-in-windows-clipboard-handler-a-critical-memory-safety-vulnerability</loc>
<lastmod>2026-06-03T10:10:00.654Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/decrypted-secrets-in-plain-sight-fixing-aes-log-exposure-in-java</loc>
<lastmod>2026-06-03T09:28:27.670Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/cve-2025-7783-critical-form-data-unsafe-randomness-vulnerability-fixed</loc>
<lastmod>2026-09-17T07:24:16.411Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-command-injection-fixed-in-python-test-script</loc>
<lastmod>2026-06-03T08:08:10.824Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/plaintext-oauth-token-storage-a-silent-security-risk-in-your-application</loc>
<lastmod>2026-06-03T10:11:28.070Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/preventing-dos-attacks-fixing-resource-exhaustion-in-file-import-systems</loc>
<lastmod>2026-06-03T10:10:53.762Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/urllib3-redirect-vulnerability-how-uncontrolled-redirects-put-your-application-at-risk</loc>
<lastmod>2026-06-03T10:11:23.112Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/google-oauth-token-exposure-how-a-leaked-access-token-put-api-security-at-risk</loc>
<lastmod>2026-06-03T10:14:06.535Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/why-strtok-is-dangerous-a-critical-security-fix-in-libscram</loc>
<lastmod>2026-06-03T10:13:20.715Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/insecure-websocket-vulnerability-why-wss-should-always-replace-ws</loc>
<lastmod>2026-06-03T08:02:51.196Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/jwt-algorithm-confusion-how-a-missing-parameter-can-compromise-authentication</loc>
<lastmod>2026-06-03T10:17:18.919Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/path-traversal-in-node-tar-how-hardlink-bypass-exposed-your-files</loc>
<lastmod>2026-06-03T10:15:09.798Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/critical-path-traversal-fix-how-node-tar-hardlink-vulnerability-was-patched</loc>
<lastmod>2026-06-03T10:11:20.637Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://orbisappsec.com/blog/unpacking-the-danger-fixing-node-tars-path-traversal-vulnerability</loc>
<lastmod>2026-06-03T10:12:21.002Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
</urlset>
