| HTTP Request Smuggling | |
| Resource Exhaustion | |
| Improper Certificate Validation | |
| Improper Input Validation | |
| Out-of-bounds Read | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| OS Command Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Uncontrolled Memory Allocation | |
| Uncontrolled Memory Allocation | |
| Resource Exhaustion | |
| Out-of-bounds Read | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Integer Overflow or Wraparound | |
| Out-of-bounds Read | |
| Uncontrolled Memory Allocation | |
| Uncontrolled Memory Allocation | |
| Integer Overflow or Wraparound | |
| Out-of-bounds Write | |
| Missing Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| Origin Validation Error | |
| Use of a Broken or Risky Cryptographic Algorithm | |
| CVE-2026-55574 | |
| CVE-2026-55514 | |
| Improper Input Validation | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-4xgf-cpjx-pc3j | |
| Information Exposure Through Log Files | |
| Misinterpretation of Input | |
| Improper Validation of Specified Type of Input | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| Information Exposure | |
| Uncontrolled Search Path Element | |
| HTTP Request Smuggling | |
| Arbitrary Code Injection | |
| Use of Incorrectly-Resolved Name or Reference | |
| Improper Input Validation | |
| Improper Validation of Specified Quantity in Input | |
| Resource Exhaustion | |
| CVE-2026-27145 | |
| Interpretation Conflict | |
| CVE-2026-48818 | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| Improper Authentication | |
| Improper Resource Shutdown or Release | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-537c-gmf6-5ccf | |
| Improper Restriction of Rendered UI Layers or Frames | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | |
| Improper Restriction of Rendered UI Layers or Frames | |
| Improper Verification of Cryptographic Signature | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| CRLF Injection | |
| Improper Initialization | |
| Resource Exhaustion | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Improper Restriction of Rendered UI Layers or Frames | |
| Cross-site Scripting (XSS) | |
| Improper Cleanup on Thrown Exception | |
| Improper Validation of Certificate with Host Mismatch | |
| Insufficient Verification of Data Authenticity | |
| CVE-2026-39821 | |
| CVE-2026-39825 | |
| CVE-2026-42499 | |
| Double Free | |
| Origin Validation Error | |
| HTTP Request Smuggling | |
| Deserialization of Untrusted Data | |
| Inefficient Regular Expression Complexity | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| Information Exposure | |
| CVE-2025-69872 | |