| Resource Exhaustion | |
| HTTP Request Smuggling | |
| Resource Exhaustion | |
| CVE-2026-59949 | |
| CRLF Injection | |
| Improper Access Control | |
| GHSA-mfg7-5gfp-c4w3 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| HTTP Request Smuggling | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-41695 | |
| CVE-2026-41848 | |
| CVE-2026-41850 | |
| CVE-2026-41852 | |
| CVE-2026-41851 | |
| Use of Non-Canonical URL Paths for Authorization Decisions | |
| Improper Handling of Alternate Encoding | |
| Information Exposure | |
| Improper Input Validation | |
| CVE-2026-10532 | |
| Deserialization of Untrusted Data | |
| Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | |
| CVE-2026-9828 | |
| Incomplete Blacklist | |
| Incomplete Blacklist | |
| CVE-2025-14813 | |
| CVE-2026-54665 | |
| CVE-2026-44913 | |
| CVE-2026-44914 | |
| CVE-2026-44911 | |
| Allocation of Resources Without Limits or Throttling | |
| HTTP Request Smuggling | |
| Resource Exhaustion | |
| Information Exposure | |
| Improper Verification of Cryptographic Signature | |
| Insufficient Verification of Data Authenticity | |
| Improper Verification of Source of a Communication Channel | |
| Use of Insufficiently Random Values | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| Resource Exhaustion | |
| Improper Access Control | |
| Insufficient Verification of Data Authenticity | |
| Improper Authentication | |
| Uncontrolled Recursion | |
| GHSA-72hv-8253-57qq | |
| Deserialization of Untrusted Data | |
| Resource Exhaustion | |
| Deserialization of Untrusted Data | |
| Deserialization of Untrusted Data | |
| Deserialization of Untrusted Data | |
| HTTP Request Smuggling | |
| Integer Overflow or Wraparound | |
| Improper Input Validation | |
| Missing Release of Resource after Effective Lifetime | |
| HTTP Request Smuggling | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| HTTP Response Splitting | |
| CRLF Injection | |
| Missing Authorization | |
| CVE-2026-22754 | |
| CVE-2026-22753 | |
| CVE-2026-22746 | |
| CVE-2026-22748 | |
| CVE-2026-22747 | |
| Missing Critical Step in Authentication | |
| CVE-2026-3505 | |
| Out-of-bounds Read | |
| CVE-2026-0636 | |
| CVE-2026-5588 | |
| CVE-2026-22751 | |
| CVE-2026-5598 | |
| Improper Validation of Specified Index, Position, or Offset in Input | |
| HTTP Request Smuggling | |
| Race Condition | |
| GHSA-2m67-wjpj-xhg9 | |
| Improper Certificate Validation | |
| Information Exposure Through Log Files | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-22732 | |