| Allocation of Resources Without Limits or Throttling | |
| Reachable Assertion | |
| Integer Overflow or Wraparound | |
| Server-Side Request Forgery (SSRF) | |
| Incorrect Authorization | |
| GHSA-qr4g-8hrp-c4rw | |
| GHSA-3xc5-wrhm-f963 | |
| CVE-2026-27143 | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Improper Certificate Validation | |
| Improper Certificate Validation | |
| Link Following | |
| Cross-site Scripting (XSS) | |
| CVE-2026-32280 | |
| Incorrect Authorization | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Certificate Validation | |
| Allocation of Resources Without Limits or Throttling | |
| Untrusted Search Path | |
| Uncaught Exception | |
| Improper Validation of Array Index | |
| Integer Underflow | |
| Improper Authorization | |
| Direct Request ('Forced Browsing') | |
| Improper Certificate Validation | |
| Cross-site Scripting (XSS) | |
| Directory Traversal | |
| Improper Certificate Validation | |
| CVE-2025-15558 | |
| Untrusted Search Path | |
| CVE-2026-1229 | |
| Improper Validation of Integrity Check Value | |