| HTTP Request Smuggling | |
| CRLF Injection | |
| Resource Exhaustion | |
| Improper Handling of Alternate Encoding | |
| Improper Access Control | |
| Use of Non-Canonical URL Paths for Authorization Decisions | |
| Resource Exhaustion | |
| CVE-2026-41852 | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-41851 | |
| Information Exposure | |
| HTTP Request Smuggling | |
| GHSA-mfg7-5gfp-c4w3 | |
| Improper Check for Certificate Revocation | |
| CVE-2026-43827 | |
| XML External Entity (XXE) Injection | |
| Use of Insufficiently Random Values | |
| Resource Exhaustion | |
| Information Exposure | |
| Information Exposure | |
| CVE-2026-41848 | |
| CRLF Injection | |
| GHSA-v74w-7mr3-4qg3 | |
| CVE-2026-41850 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| CVE-2026-59949 | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| CRLF Injection | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Improper Input Validation | |
| Resource Exhaustion | |
| Time-of-check Time-of-use (TOCTOU) | |
| Resource Exhaustion | |
| Improper Certificate Validation | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Check or Handling of Exceptional Conditions | |
| Resource Exhaustion | |
| Improper Access Control | |
| Improper Verification of Source of a Communication Channel | |
| Allocation of Resources Without Limits or Throttling | |
| LDAP Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Memory Leak | |
| Resource Exhaustion | |
| Improper Verification of Cryptographic Signature | |
| Incomplete Blacklist | |
| Memory Leak | |
| Incomplete Blacklist | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Insufficient Verification of Data Authenticity | |
| Insufficient Verification of Data Authenticity | |