| Creation of Immutable Text Using String Concatenation | |
| Link Following | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Output Neutralization for Logs | |
| Expected Behavior Violation | |
| Expected Behavior Violation | |
| Allocation of Resources Without Limits or Throttling | |
| Time-of-check Time-of-use (TOCTOU) | |
| CVE-2025-4673 | |
| HTTP Request Smuggling | |
| Incorrect Authorization | |
| Incorrect Authorization | |
| Improper Input Validation | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Directory Traversal | |
| Directory Traversal | |
| Information Exposure | |
| Improper Verification of Cryptographic Signature | |
| Improper Privilege Management | |
| Link Following | |
| Use of Uninitialized Variable | |
| Improper Input Validation | |
| Improperly Controlled Sequential Memory Allocation | |
| Uncontrolled Recursion | |
| Uncontrolled Recursion | |
| Improper Input Validation | |
| Improper Validation of Integrity Check Value | |
| Memory Leak | |
| Link Following | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| Resource Exhaustion | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Improper Input Validation | |
| Improper Input Validation | |
| Truncation of Security-relevant Information | |
| Information Exposure | |
| Resource Exhaustion | |
| Buffer Access with Incorrect Length Value | |
| Cross-site Scripting (XSS) | |
| Allocation of Resources Without Limits or Throttling | |
| Cross-site Scripting (XSS) | |
| Resource Exhaustion | |
| HTTP Response Splitting | |
| Improper Handling of Unicode Encoding | |
| Improper Handling of Unicode Encoding | |
| Improper Handling of Unicode Encoding | |
| Resource Exhaustion | |
| Arbitrary Code Injection | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Placement of User into Incorrect Group | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2022-41715 | |
| Allocation of Resources Without Limits or Throttling | |
| HTTP Request Smuggling | |
| Resource Exhaustion | |
| Placement of User into Incorrect Group | |
| Placement of User into Incorrect Group | |
| Resource Exhaustion | |
| Information Exposure | |
| Improperly Controlled Sequential Memory Allocation | |
| Improperly Controlled Sequential Memory Allocation | |
| Improperly Controlled Sequential Memory Allocation | |
| HTTP Request Smuggling | |
| Insufficient Entropy | |
| Use of a Broken or Risky Cryptographic Algorithm | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Race Condition | |
| Improper Input Validation | |
| Resource Exhaustion | |
| Improper Input Validation | |
| Improper Input Validation | |
| Improper Input Validation | |
| Improper Locking | |