| Improper Access Control | |
| Incorrect Authorization | |
| Information Exposure Through Caching | |
| Algorithmic Complexity | |
| Improper Check for Unusual or Exceptional Conditions | |
| Insufficiently Protected Credentials | |
| Inappropriate Encoding for Output Context | |
| Cleartext Transmission of Sensitive Information | |
| CVE-2026-40984 | |
| CVE-2026-40983 | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| CRLF Injection | |
| Improper Access Control | |
| CRLF Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| GHSA-mfg7-5gfp-c4w3 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Improper Authentication | |
| Not Failing Securely ('Failing Open') | |
| GHSA-mhm7-754m-9p8w | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |