Per [NIST](https://nvd.nist.gov/vuln/detail/CVE-2022-36640) it only affects < 1.8.0, yet this index marks later versions as vulnerable to this. E.g. https://github.com/sonatype-nexus-community/nancy/issues/278#issuecomment-2732883003