| Resource Exhaustion | |
| CRLF Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Improper Access Control | |
| HTTP Request Smuggling | |
| Incorrect Authorization | |
| GHSA-r7wm-3cxj-wff9 | |
| HTTP Request Smuggling | |
| CVE-2026-41695 | |
| CVE-2026-41842 | |
| CVE-2026-41846 | |
| CVE-2026-41851 | |
| CVE-2026-41843 | |
| CVE-2026-41848 | |
| CVE-2026-41853 | |
| CVE-2026-41844 | |
| CVE-2026-41850 | |
| CVE-2026-41852 | |
| CVE-2026-41845 | |
| CVE-2026-41841 | |
| Missing Release of Resource after Effective Lifetime | |
| Improper Handling of Alternate Encoding | |
| Information Exposure | |
| Use of Non-Canonical URL Paths for Authorization Decisions | |
| Improper Input Validation | |
| GHSA-mhm7-754m-9p8w | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| CVE-2026-10532 | |
| CVE-2026-9828 | |
| CVE-2025-14813 | |
| Incomplete Blacklist | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Incorrect Authorization | |
| Server-Side Request Forgery (SSRF) | |
| Incomplete Blacklist | |
| Incorrect Authorization | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| Improper Verification of Cryptographic Signature | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Access Control | |
| Resource Exhaustion | |
| CVE-2026-40976 | |
| CVE-2026-40973 | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| CVE-2026-22741 | |
| HTTP Request Smuggling | |
| Integer Overflow or Wraparound | |
| HTTP Request Smuggling | |
| CRLF Injection | |
| CVE-2026-22747 | |
| CVE-2026-22746 | |
| CVE-2026-22754 | |
| CVE-2026-22753 | |
| CVE-2026-22751 | |
| CVE-2026-5598 | |
| CVE-2026-0636 | |
| CVE-2026-3505 | |
| CVE-2026-5588 | |
| HTTP Request Smuggling | |
| CVE-2026-22733 | |
| Allocation of Resources Without Limits or Throttling | |
| Missing Authentication for Critical Function | |
| CVE-2026-22735 | |
| CVE-2026-22737 | |
| CVE-2026-22732 | |
| GHSA-72hv-8253-57qq | |
| GHSA-2m67-wjpj-xhg9 | |