| HTTP Request Smuggling | |
| Allocation of Resources Without Limits or Throttling | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Unchecked Input for Loop Condition | |
| Improper Null Termination | |
| Misinterpretation of Input | |
| Inefficient Regular Expression Complexity | |
| Authentication Bypass | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Information Exposure | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Incorrect Use of Privileged APIs | |
| Incorrect Execution-Assigned Permissions | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Null Termination | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Authentication Bypass | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Certificate Validation | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Allocation of Resources Without Limits or Throttling | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Allocation of Resources Without Limits or Throttling | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Validation of Syntactic Correctness of Input | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Verification of Source of a Communication Channel | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| CRLF Injection | |
| Improper Certificate Validation | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Verification of Source of a Communication Channel | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Validation of Syntactic Correctness of Input | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Allocation of Resources Without Limits or Throttling | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Allocation of Resources Without Limits or Throttling | |
| Cross-site Scripting (XSS) | <1:24.18.0-1.module+el9.8.0+24456+b244c3b4 |
| Improper Verification of Source of a Communication Channel | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Reversible One-Way Hash | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Incorrect Execution-Assigned Permissions | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Missing Release of Resource after Effective Lifetime | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Access of Resource Using Incompatible Type ('Type Confusion') | <1:20.20.2-1.module+el9.7.0+24193+41b7b572 |
| Direct Request ('Forced Browsing') | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Information Exposure | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Improper Handling of Inconsistent Special Elements | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Unchecked Input for Loop Condition | |
| Inefficient Regular Expression Complexity | |
| Executable Regular Expression Error | |
| Reachable Assertion | <1:20.20.2-1.module+el9.7.0+24193+41b7b572 |
| Inefficient Regular Expression Complexity | |
| Inefficient Regular Expression Complexity | <1:20.20.2-1.module+el9.7.0+24193+41b7b572 |
| Inefficient Regular Expression Complexity | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| Uncaught Exception | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Allocation of Resources Without Limits or Throttling | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| CRLF Injection | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| HTTP Request Smuggling | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Uncaught Exception | <1:24.14.1-2.module+el9.7.0+24166+51c9666b |
| Use of Uninitialized Resource | |
| Exposure of System Data to an Unauthorized Control Sphere | <1:20.20.0-1.module+el9.7.0+23895+0637d423 |
| Uncaught Exception | <1:20.20.0-1.module+el9.7.0+23895+0637d423 |
| Improper Preservation of Permissions | <1:20.20.0-1.module+el9.7.0+23895+0637d423 |
| Allocation of Resources Without Limits or Throttling | |
| Improper Preservation of Permissions | <1:20.20.0-1.module+el9.7.0+23895+0637d423 |
| Allocation of Resources Without Limits or Throttling | <1:20.20.0-1.module+el9.7.0+23895+0637d423 |
| Uncaught Exception | <1:20.20.0-1.module+el9.7.0+23895+0637d423 |
| Time-of-check Time-of-use (TOCTOU) | |
| Allocation of Resources Without Limits or Throttling | |
| Use After Free | |
| OS Command Injection | |
| Numeric Truncation Error | <1:22.16.0-2.module+el9.6.0+23339+d3c8acfa |
| Inefficient Regular Expression Complexity | |
| Inefficient Regular Expression Complexity | |
| HTTP Request Smuggling | <1:20.19.2-1.module+el9.6.0+23146+be9976bd |
| Uncaught Exception | <1:22.16.0-1.module+el9.6.0+23151+b1496e9d |
| Memory Leak | <1:22.16.0-1.module+el9.6.0+23151+b1496e9d |
| Memory Leak | |
| Heap-based Buffer Overflow | <1:22.15.0-1.module+el9.6.0+23062+9e7801b9 |
| Use After Free | <1:22.15.0-1.module+el9.6.0+23062+9e7801b9 |
| Resource Exhaustion | <1:18.20.6-1.module+el9.5.0+22773+9a359385 |
| Use of Insufficiently Random Values | <1:18.20.6-1.module+el9.5.0+22773+9a359385 |
| Incorrect Authorization | <1:20.18.2-1.module+el9.5.0+22758+4ad2c198 |
| Resource Exhaustion | <1:18.20.4-1.module+el9.4.0+22195+c221878e |
| Incorrect Permission Assignment for Critical Resource | <1:20.16.0-1.module+el9.4.0+22197+9e60f127 |
| CVE-2024-22020 | <1:18.20.4-1.module+el9.4.0+22195+c221878e |
| CVE-2024-22018 | <1:20.16.0-1.module+el9.4.0+22197+9e60f127 |
| HTTP Request Smuggling | <1:18.20.2-2.module+el9.4.0+21742+692df1ea |
| Detection of Error Condition Without Action | <1:18.20.2-2.module+el9.4.0+21742+692df1ea |
| Resource Exhaustion | <1:18.20.2-2.module+el9.4.0+21742+692df1ea |
| Resource Exhaustion | <1:18.20.2-2.module+el9.4.0+21742+692df1ea |
| Buffer Under-read | <1:18.20.2-2.module+el9.4.0+21742+692df1ea |
| Improper Privilege Management | <1:20.11.1-1.module+el9.3.0+21385+bac43d5a |
| Incomplete Documentation | <1:20.11.1-1.module+el9.3.0+21385+bac43d5a |
| Directory Traversal | <1:20.11.1-1.module+el9.3.0+21385+bac43d5a |
| Directory Traversal | <1:20.11.1-1.module+el9.3.0+21385+bac43d5a |
| Resource Exhaustion | <1:18.19.1-1.module+el9.3.0+21388+22892fb9 |
| Arbitrary Code Injection | <1:18.19.1-1.module+el9.3.0+21388+22892fb9 |
| Covert Timing Channel | <1:18.19.1-1.module+el9.3.0+21388+22892fb9 |
| Server-Side Request Forgery (SSRF) | |
| Information Exposure | <1:18.18.2-2.module+el9.2.0.z+20408+7cb5fda5 |
| Improper Validation of Integrity Check Value | <1:18.18.2-2.module+el9.2.0.z+20408+7cb5fda5 |
| Arbitrary Code Injection | <1:18.18.2-2.module+el9.2.0.z+20408+7cb5fda5 |
| Directory Traversal | <1:20.9.0-1.module+el9.3.0.z+20633+3a660725 |
| Resource Exhaustion | |
| Arbitrary Code Injection | <1:18.17.1-1.module+el9.2.0.z+19753+58118bc0 |
| Information Exposure | <1:18.17.1-1.module+el9.2.0.z+19753+58118bc0 |
| Reliance on Untrusted Inputs in a Security Decision | <1:18.17.1-1.module+el9.2.0.z+19753+58118bc0 |
| Inefficient Regular Expression Complexity | <1:18.17.1-1.module+el9.2.0.z+19753+58118bc0 |
| CVE-2023-30588 | |
| CVE-2023-30589 | |
| CVE-2023-30581 | |
| CVE-2023-30590 | |
| Out-of-bounds Write | |
| Use of Insufficiently Random Values | |
| Resource Exhaustion | |
| Use of Insufficiently Random Values | |
| Inefficient Regular Expression Complexity | <1:18.14.2-2.module+el9.2.0.z+18497+a402347c |
| CRLF Injection | <1:18.14.2-2.module+el9.2.0.z+18497+a402347c |
| Untrusted Search Path | <1:18.14.2-2.module+el9.2.0.z+18497+a402347c |
| CVE-2023-23919 | <1:18.14.2-2.module+el9.2.0.z+18497+a402347c |
| Incorrect Authorization | <1:18.14.2-2.module+el9.2.0.z+18497+a402347c |
| Buffer Access with Incorrect Length Value | <1:18.14.2-2.module+el9.2.0.z+18497+a402347c |
| Inefficient Regular Expression Complexity | <1:18.14.2-2.module+el9.2.0.z+18497+a402347c |
| Resource Exhaustion | <1:18.14.2-2.module+el9.2.0.z+18497+a402347c |
| Reliance on Reverse DNS Resolution for a Security-Critical Action | <1:18.12.1-1.module+el9.1.0.z+17326+318294bb |
| Inefficient Regular Expression Complexity | <1:18.12.1-1.module+el9.1.0.z+17326+318294bb |
| Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | |
| HTTP Request Smuggling | |
| HTTP Request Smuggling | |
| HTTP Request Smuggling | |
| Improper Check or Handling of Exceptional Conditions | |
| HTTP Request Smuggling | |
| Open Redirect | |
| Improper Cross-boundary Removal of Sensitive Data | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |