| CVE-2025-14813 | |
| Server-Side Request Forgery (SSRF) | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Incomplete Blacklist | |
| Incomplete Blacklist | |
| GHSA-wjv4-x9w8-wm3h | |
| GHSA-p67v-3w7g-wjg7 | |
| GHSA-wfpw-mmfh-qq69 | |
| GHSA-9cv2-cfxc-v4v2 | |
| GHSA-5v8h-3h3q-446p | |
| GHSA-phwj-rprq-35pp | |
| GHSA-5prr-v3j2-97mh | |
| GHSA-8678-w3jw-xfc2 | |
| Uncontrolled Recursion | |
| CVE-2026-54905 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Missing Lock Check | |
| Improper Verification of Cryptographic Signature | |
| HTTP Request Smuggling | |
| Arbitrary Command Injection | |
| Arbitrary Command Injection | |
| Improper Neutralization | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Access Control | |
| Authentication Bypass | |
| Resource Exhaustion | |
| Server-Side Request Forgery (SSRF) | |
| Information Exposure | |
| CVE-2025-12183 | |
| Arbitrary Command Injection | |
| CRLF Injection | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| HTTP Request Smuggling | |
| GHSA-v2fc-qm4h-8hqv | |
| Resource Exhaustion | |
| Integer Overflow or Wraparound | |
| GHSA-c4rq-3m3g-8wgx | |
| HTTP Request Smuggling | |
| NULL Pointer Dereference | |
| CVE-2026-42501 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Improper Encoding or Escaping of Output | |
| CVE-2026-42499 | |
| Allocation of Resources Without Limits or Throttling | |
| Link Following | |
| Out-of-bounds Write | |
| Double Free | |
| Cross-site Scripting (XSS) | |
| CVE-2026-39825 | |
| Allocation of Resources Without Limits or Throttling | |
| Missing Report of Error Condition | |
| Algorithmic Complexity | |
| Arbitrary Command Injection | |
| Resource Exhaustion | |
| Improper Validation of Syntactic Correctness of Input | |
| Interpretation Conflict | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Permissive Regular Expression | |
| Inefficient Regular Expression Complexity | |
| CRLF Injection | |
| Improper Handling of Length Parameter Inconsistency | |
| Permissive Regular Expression | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| Resource Exhaustion | |
| Interpretation Conflict | |
| Improper Authentication | |
| Partial Comparison | |
| Improper Validation of Certificate with Host Mismatch | |
| Improper Encoding or Escaping of Output | |
| CVE-2026-5588 | |
| CVE-2026-0636 | |
| Improper Output Neutralization for Logs | |
| Improper Encoding or Escaping of Output | |
| CVE-2026-5598 | |
| Protection Mechanism Failure | |
| Information Exposure Through Server Log Files | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| CVE-2026-27143 | |
| Race Condition | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Certificate Validation | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-32280 | |
| Cross-site Scripting (XSS) | |
| Incorrect Authorization | |
| Link Following | |
| Use of Externally-Controlled Format String | |
| HTTP Request Smuggling | |
| Uncontrolled Recursion | |
| GHSA-72hv-8253-57qq | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Direct Request ('Forced Browsing') | |
| Directory Traversal | |
| Arbitrary Code Injection | |
| Cross-site Scripting (XSS) | |
| GHSA-wx95-c6cv-8532 | |
| Server-Side Request Forgery (SSRF) | |
| CVE-2025-68121 | |
| CVE-2025-61732 | |
| CVE-2025-61731 | |
| CVE-2025-61730 | |
| Allocation of Resources Without Limits or Throttling | |
| Out-of-bounds Write | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| Improper Certificate Validation | |
| CVE-2025-14762 | |
| CRLF Injection | |
| Improper Certificate Validation | |
| Improper Certificate Validation | |
| Resource Exhaustion | |
| Inefficient Regular Expression Complexity | |