| CVE-2026-13506 | |
| CVE-2026-8763 | |
| Algorithmic Complexity | |
| Improper Check for Unusual or Exceptional Conditions | |
| Resource Exhaustion | |
| Information Exposure Through Caching | |
| Improper Check for Certificate Revocation | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Incomplete Blacklist | |
| GHSA-mhm7-754m-9p8w | |
| Resource Exhaustion | |
| Use of Non-Canonical URL Paths for Authorization Decisions | |
| CRLF Injection | |
| Resource Exhaustion | |
| CRLF Injection | |
| Missing Release of Resource after Effective Lifetime | |
| Resource Exhaustion | |
| Time-of-check Time-of-use (TOCTOU) | |
| Information Exposure | |
| Memory Leak | |
| Allocation of Resources Without Limits or Throttling | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Missing Release of Resource after Effective Lifetime | |
| Incorrect Authorization | |
| Uncontrolled Recursion | |
| Server-Side Request Forgery (SSRF) | |
| Incorrect Authorization | |
| Resource Exhaustion | |
| Cross-site Scripting (XSS) | |
| CRLF Injection | |
| GHSA-r7wm-3cxj-wff9 | |
| CVE-2026-54399 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| HTTP Request Smuggling | |
| Incorrect Authorization | |
| Resource Exhaustion | |
| XML External Entity (XXE) Injection | |
| Improper Input Validation | |
| HTTP Request Smuggling | |
| Improper Access Control | |
| CVE-2026-54428 | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Incomplete Blacklist | |
| Resource Exhaustion | |
| Improper Handling of Alternate Encoding | |
| NULL Pointer Dereference | |
| Improper Encoding or Escaping of Output | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Not Failing Securely ('Failing Open') | |
| Improper Certificate Validation | |