| HTTP Request Smuggling | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Allocation of Resources Without Limits or Throttling | |
| Unchecked Input for Loop Condition | |
| Improper Null Termination | |
| Misinterpretation of Input | |
| Inefficient Regular Expression Complexity | |
| Authentication Bypass | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Information Exposure | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Incorrect Use of Privileged APIs | |
| Incorrect Execution-Assigned Permissions | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Null Termination | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Authentication Bypass | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Certificate Validation | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Allocation of Resources Without Limits or Throttling | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Allocation of Resources Without Limits or Throttling | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Validation of Syntactic Correctness of Input | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| CRLF Injection | |
| Improper Verification of Source of a Communication Channel | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Certificate Validation | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Verification of Source of a Communication Channel | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Validation of Syntactic Correctness of Input | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Allocation of Resources Without Limits or Throttling | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Allocation of Resources Without Limits or Throttling | |
| Cross-site Scripting (XSS) | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Verification of Source of a Communication Channel | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Reversible One-Way Hash | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Incorrect Execution-Assigned Permissions | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Missing Release of Resource after Effective Lifetime | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Access of Resource Using Incompatible Type ('Type Confusion') | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Direct Request ('Forced Browsing') | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Information Exposure | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Improper Handling of Inconsistent Special Elements | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Unchecked Input for Loop Condition | |
| Inefficient Regular Expression Complexity | |
| Executable Regular Expression Error | |
| Reachable Assertion | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Inefficient Regular Expression Complexity | |
| Inefficient Regular Expression Complexity | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Inefficient Regular Expression Complexity | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| Uncaught Exception | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Allocation of Resources Without Limits or Throttling | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| CRLF Injection | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| HTTP Request Smuggling | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Uncaught Exception | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Use of Uninitialized Resource | |
| Exposure of System Data to an Unauthorized Control Sphere | <1:24.13.0-1.module+el9.7.0+23894+c8377628 |
| Uncaught Exception | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Improper Preservation of Permissions | <1:24.13.0-1.module+el9.7.0+23894+c8377628 |
| Allocation of Resources Without Limits or Throttling | |
| Improper Preservation of Permissions | <1:24.13.0-1.module+el9.7.0+23894+c8377628 |
| Allocation of Resources Without Limits or Throttling | <1:24.13.0-1.module+el9.7.0+23894+c8377628 |
| Uncaught Exception | <1:24.13.0-1.module+el9.7.0+23894+c8377628 |
| Time-of-check Time-of-use (TOCTOU) | |
| Allocation of Resources Without Limits or Throttling | |
| Use After Free | |
| OS Command Injection | |
| Numeric Truncation Error | <1:22.16.0-2.module+el9.6.0+23339+d3c8acfa |
| Inefficient Regular Expression Complexity | |
| Inefficient Regular Expression Complexity | |
| HTTP Request Smuggling | |
| Uncaught Exception | <1:22.16.0-1.module+el9.6.0+23151+b1496e9d |
| Memory Leak | <1:22.16.0-1.module+el9.6.0+23151+b1496e9d |
| Memory Leak | |
| Heap-based Buffer Overflow | <1:22.15.0-1.module+el9.6.0+23062+9e7801b9 |
| Use After Free | <1:22.15.0-1.module+el9.6.0+23062+9e7801b9 |
| Resource Exhaustion | <1:22.13.1-1.module+el9.5.0+22763+17233acb |
| Use of Insufficiently Random Values | <1:22.13.1-1.module+el9.5.0+22763+17233acb |
| Incorrect Authorization | <1:22.13.1-1.module+el9.5.0+22763+17233acb |
| HTTP Request Smuggling | |
| Detection of Error Condition Without Action | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Buffer Under-read | |
| Improper Privilege Management | |
| Incomplete Documentation | |
| Directory Traversal | |
| Directory Traversal | |
| Resource Exhaustion | |
| Arbitrary Code Injection | |
| Covert Timing Channel | |
| Server-Side Request Forgery (SSRF) | |
| Information Exposure | |
| Improper Validation of Integrity Check Value | |
| Arbitrary Code Injection | |
| Resource Exhaustion | |
| Arbitrary Code Injection | |
| Information Exposure | |
| Reliance on Untrusted Inputs in a Security Decision | |
| Inefficient Regular Expression Complexity | |
| CVE-2023-30588 | |
| CVE-2023-30589 | |
| CVE-2023-30581 | |
| CVE-2023-30590 | |
| Out-of-bounds Write | |
| Use of Insufficiently Random Values | |
| Resource Exhaustion | |
| Use of Insufficiently Random Values | |
| Inefficient Regular Expression Complexity | |
| CRLF Injection | |
| Untrusted Search Path | |
| Incorrect Authorization | |
| Buffer Access with Incorrect Length Value | |
| Inefficient Regular Expression Complexity | |
| Resource Exhaustion | |
| Reliance on Reverse DNS Resolution for a Security-Critical Action | |
| Inefficient Regular Expression Complexity | |
| Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | |
| HTTP Request Smuggling | |
| HTTP Request Smuggling | |
| HTTP Request Smuggling | |
| Improper Check or Handling of Exceptional Conditions | |
| HTTP Request Smuggling | |
| Open Redirect | |
| Improper Cross-boundary Removal of Sensitive Data | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |