| Incorrect Authorization | |
| Incomplete Blacklist | |
| Resource Exhaustion | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| GHSA-mhm7-754m-9p8w | |
| Server-Side Request Forgery (SSRF) | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| Resource Exhaustion | |
| Improper Access Control | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Incorrect Authorization | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Incomplete Blacklist | |
| CRLF Injection | |
| Incorrect Authorization | |
| Missing Release of Resource after Effective Lifetime | |
| HTTP Request Smuggling | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Verification of Cryptographic Signature | |
| Resource Exhaustion | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Access Control | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Integer Overflow or Wraparound | |
| HTTP Request Smuggling | |
| Resource Exhaustion | |
| HTTP Request Smuggling | |
| HTTP Request Smuggling | |
| CRLF Injection | |
| Improper Encoding or Escaping of Output | |
| CVE-2026-5598 | |
| Information Exposure Through Server Log Files | |
| Improper Validation of Specified Index, Position, or Offset in Input | |
| CVE-2026-0636 | |
| CVE-2026-5588 | |
| Improper Neutralization | |
| Race Condition | |
| HTTP Request Smuggling | |
| Allocation of Resources Without Limits or Throttling | |
| Deserialization of Untrusted Data | |
| GHSA-72hv-8253-57qq | |
| Improper Certificate Validation | |
| CRLF Injection | |
| XML External Entity (XXE) Injection | |
| Uncontrolled Recursion | |
| CVE-2025-12194 | |
| Uncontrolled Recursion | |
| CVE-2025-8916 | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| CVE-2025-48734 | |
| Uncontrolled Recursion | |
| CVE-2025-22227 | |
| XML External Entity (XXE) Injection | |
| HTTP Request Smuggling | |
| CVE-2025-8885 | |
| Allocation of Resources Without Limits or Throttling | |