| Improper Check for Unusual or Exceptional Conditions | |
| Algorithmic Complexity | |
| Authentication Bypass | |
| Improper Access Control | |
| Incorrect Authorization | |
| CVE-2026-41001 | |
| Missing Release of Resource after Effective Lifetime | |
| Information Exposure Through Caching | |
| Improper Encoding or Escaping of Output | |
| CVE-2026-54428 | |
| CVE-2026-41697 | |
| CVE-2026-41706 | |
| CVE-2026-41721 | |
| CVE-2026-54399 | |
| CVE-2026-41711 | |
| CVE-2026-41716 | |
| CVE-2026-40984 | |
| CVE-2026-40983 | |
| CVE-2026-41854 | |
| CVE-2026-41695 | |
| Resource Exhaustion | |
| CVE-2026-41853 | |
| CVE-2026-41843 | |
| CVE-2026-41844 | |
| CVE-2026-41846 | |
| CVE-2026-41842 | |
| CVE-2026-41848 | |
| CVE-2026-41845 | |
| CVE-2026-41850 | |
| CVE-2026-41852 | |
| CVE-2026-41851 | |
| CVE-2026-41841 | |
| GHSA-mfg7-5gfp-c4w3 | |
| Improper Access Control | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| Incorrect Authorization | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| CRLF Injection | |
| GHSA-mhm7-754m-9p8w | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| HTTP Request Smuggling | |
| GHSA-r7wm-3cxj-wff9 | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Not Failing Securely ('Failing Open') | |
| CVE-2026-47838 | |
| HTTP Request Smuggling | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Incomplete Blacklist | |
| Incorrect Authorization | |
| Incorrect Authorization | |
| Server-Side Request Forgery (SSRF) | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Incomplete Blacklist | |
| Improper Verification of Cryptographic Signature | |
| Insufficient Verification of Data Authenticity | |
| Improper Access Control | |
| Information Exposure | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Use of Insufficiently Random Values | |
| Insufficient Verification of Data Authenticity | |
| CVE-2025-37731 | |
| CVE-2025-37727 | |
| CVE-2024-52980 | |
| Resource Exhaustion | |
| Improper Authorization | |
| Resource Exhaustion | |
| Integer Overflow or Wraparound | |
| Information Exposure | |
| HTTP Request Smuggling | |
| Improper Input Validation | |
| Improper Input Validation | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| Authentication Bypass | |
| HTTP Request Smuggling | |
| HTTP Response Splitting | |
| CRLF Injection | |
| HTTP Request Smuggling | |
| Improper Handling of Case Sensitivity | |