| Allocation of Resources Without Limits or Throttling | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Insufficient Verification of Data Authenticity | |
| Allocation of Resources Without Limits or Throttling | |
| Authentication Bypass | |
| Deserialization of Untrusted Data | |
| Deserialization of Untrusted Data | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Validation of Specified Type of Input | |
| CVE-2026-56158 | |
| Arbitrary Code Injection | |
| Incorrect Implementation of Authentication Algorithm | |
| LDAP Injection | |
| Stack-based Buffer Overflow | |
| Link Following | |
| Improper Encoding or Escaping of Output | |
| Resource Exhaustion | |
| Improper Authorization | |
| Link Following | |
| Out-of-bounds Read | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| External Control of File Name or Path | |
| Improper Input Validation | |
| CVE-2025-24070 | |
| Improper Input Validation | |
| Improper Neutralization of Special Elements | |
| Untrusted Search Path | |
| Link Following | |
| Directory Traversal | |
| Inadequate Encryption Strength | |
| CVE-2025-21173 | |
| Resource Exhaustion | |
| Protection Mechanism Failure | |
| Heap-based Buffer Overflow | |
| Improper Handling of Missing Special Element | |
| Improper Input Validation | |
| HTTP Request Smuggling | |
| Buffer Over-read | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| CVE-2025-21172 | |