| Allocation of Resources Without Limits or Throttling | |
| Improper Certificate Validation | |
| Uncontrolled Memory Allocation | |
| Uncontrolled Recursion | |
| Improper Input Validation | |
| CVE-2026-54399 | |
| Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | |
| Improper Input Validation | |
| CVE-2026-54428 | |
| Resource Exhaustion | |
| CVE-2026-40983 | |
| CVE-2026-40984 | |
| Resource Exhaustion | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| Improper Access Control | |
| Missing Release of Resource after Effective Lifetime | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| CRLF Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Encoding or Escaping of Output | |
| Incomplete Blacklist | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| CVE-2026-41844 | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| CVE-2024-52979 | |
| Improper Verification of Cryptographic Signature | |
| GHSA-72hv-8253-57qq | |
| CVE-2026-41851 | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2025-41249 | |
| Improper Access Control | |
| Server-Side Request Forgery (SSRF) | |
| CVE-2026-22741 | |
| Integer Overflow or Wraparound | |
| Incorrect Default Permissions | |
| CVE-2026-41848 | |
| HTTP Request Smuggling | |
| CVE-2026-41713 | |
| Incomplete Blacklist | |
| CRLF Injection | |
| CVE-2026-41852 | |
| Improper Validation of Certificate with Host Mismatch | |
| CVE-2024-52981 | |
| Origin Validation Error | |
| HTTP Request Smuggling | |
| CVE-2026-41845 | |
| CRLF Injection | |
| Improper Handling of Exceptional Conditions | |
| Resource Exhaustion | |
| CVE-2025-41234 | |
| CVE-2026-41841 | |
| CVE-2026-41850 | |
| CVE-2025-22233 | |
| CVE-2026-40973 | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| CVE-2026-41853 | |
| CVE-2026-41840 | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-41842 | |
| Information Exposure Through Log Files | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| Use of Insufficiently Random Values | |
| HTTP Request Smuggling | |
| Missing Encryption of Sensitive Data | |
| Improper Certificate Validation | |
| Information Exposure Through Log Files | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| CVE-2025-22227 | |
| CVE-2024-23450 | |
| CVE-2026-22740 | |
| Improper Output Neutralization for Logs | |
| CVE-2026-41843 | |
| HTTP Request Smuggling | |
| CVE-2025-41242 | |
| CVE-2026-22735 | |
| CVE-2026-22745 | |
| HTTP Response Splitting | |
| CVE-2026-22746 | |
| CVE-2026-41846 | |
| Server-Side Request Forgery (SSRF) | |
| CVE-2026-41839 | |
| GHSA-r7wm-3cxj-wff9 | |
| Resource Exhaustion | |
| CVE-2026-22737 | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| Insufficient Verification of Data Authenticity | |
| Insufficient Verification of Data Authenticity | |
| HTTP Request Smuggling | |
| Improper Input Validation | |
| Out-of-bounds Write | |
| Authentication Bypass | |
| Improper Input Validation | |
| CVE-2025-27817 | |
| Improper Authorization | |