| Incorrect Authorization | |
| GHSA-r7wm-3cxj-wff9 | |
| CVE-2026-41695 | |
| CVE-2026-41851 | |
| CVE-2026-41848 | |
| CVE-2026-41850 | |
| CVE-2026-41852 | |
| Improper Handling of Alternate Encoding | |
| Information Exposure | |
| Use of Non-Canonical URL Paths for Authorization Decisions | |
| Improper Input Validation | |
| GHSA-mhm7-754m-9p8w | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| CVE-2026-10532 | |
| CVE-2026-9828 | |
| CVE-2025-14813 | |
| Incomplete Blacklist | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Incorrect Authorization | |
| Server-Side Request Forgery (SSRF) | |
| Incomplete Blacklist | |
| Incorrect Authorization | |
| CVE-2026-40976 | |
| CVE-2026-40973 | |
| CVE-2026-22747 | |
| CVE-2026-22746 | |
| CVE-2026-22754 | |
| CVE-2026-22753 | |
| CVE-2026-22751 | |
| CVE-2026-5598 | |
| CVE-2026-0636 | |
| CVE-2026-3505 | |
| CVE-2026-5588 | |
| HTTP Request Smuggling | |
| CVE-2026-22733 | |
| Allocation of Resources Without Limits or Throttling | |
| Missing Authentication for Critical Function | |
| CVE-2026-22735 | |
| CVE-2026-22737 | |
| CVE-2026-22732 | |
| GHSA-72hv-8253-57qq | |
| GHSA-2m67-wjpj-xhg9 | |