| Resource Exhaustion | |
| Uncaught Exception | |
| Interpretation Conflict | |
| Incorrect Type Conversion or Cast | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Cross-site Scripting (XSS) | |
| Excessive Iteration | |
| Algorithmic Complexity | |
| Information Exposure | |
| Open Redirect | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure Through Caching | |
| Server-Side Request Forgery (SSRF) | |
| Improper Encoding or Escaping of Output | |
| Uncaught Exception | |
| GHSA-f88m-g3jw-g9cj | |
| Allocation of Resources Without Limits or Throttling | |
| OS Command Injection | |
| GHSA-wqvq-jvpq-h66f | |
| CVE-2026-9678 | |
| CVE-2026-39410 | |
| Incorrect Regular Expression | |
| HTTP Request Smuggling | |
| Directory Traversal | |
| Incorrect Regular Expression | |
| Arbitrary Code Injection | |
| Inappropriate Comment Style | |
| GHSA-gq3j-xvxp-8hrf | |
| Cleartext Transmission of Sensitive Information | |
| GHSA-268h-hp4c-crq3 | |
| Improper Authorization | |
| Insufficient Verification of Data Authenticity | |
| Improper Encoding or Escaping of Output | |
| Cross-site Scripting (XSS) | |
| Resource Exhaustion | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| CVE-2026-56761 | |
| HTTP Response Splitting | |
| Information Exposure | |
| Arbitrary Code Injection | |
| Use of Less Trusted Source | |
| Use of Uninitialized Resource | |
| GHSA-26pp-8wgv-hjvm | |
| Information Exposure Through Caching | |
| Resource Exhaustion | |
| Arbitrary Code Injection | |
| Directory Traversal | |
| GHSA-v8w9-8mx6-g223 | |
| Information Exposure | |
| Cross-site Request Forgery (CSRF) | |
| Improper Validation of Specified Quantity in Input | |
| GHSA-r7g4-qg5f-qqm2 | |
| GHSA-q7jf-gf43-6x6p | |
| Uncaught Exception | |
| Directory Traversal | |
| Information Exposure Through Caching | |
| CVE-2024-55565 | |
| CVE-2024-28863 | |
| Inefficient Regular Expression Complexity | |
| CVE-2021-23368 | |
| Arbitrary Code Injection | |
| Cross-site Scripting (XSS) | |
| Server-Side Request Forgery (SSRF) | |
| Inefficient Regular Expression Complexity | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-1525 | |
| Information Exposure | |
| Server-Side Request Forgery (SSRF) | |
| Directory Traversal | |
| Inefficient Regular Expression Complexity | |
| CVE-2026-8723 | |
| CVE-2026-4926 | |
| GHSA-h25m-26qc-wcjf | |
| Uncaught Exception | |
| Inefficient Regular Expression Complexity | |
| CVE-2025-9910 | |
| Authentication Bypass | |
| Directory Traversal | |
| Information Exposure | |
| CVE-2026-3635 | |
| CVE-2025-48068 | |
| CVE-2026-2229 | |
| Improper Handling of Unicode Encoding | |
| Allocation of Resources Without Limits or Throttling | |
| Race Condition | |
| Improper Verification of Cryptographic Signature | |
| Information Exposure Through Caching | |
| Inefficient Regular Expression Complexity | |
| CVE-2025-22869 | |
| GHSA-6v7q-wjvx-w8wg | |
| Authentication Bypass | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Deserialization of Untrusted Data | |
| Interpretation Conflict | |
| GHSA-8h8q-6873-q5fj | |
| Resource Exhaustion | |
| Race Condition | |
| CVE-2026-6734 | |
| Improper Certificate Validation | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| Directory Traversal | |
| Arbitrary Code Injection | |
| Reachable Assertion | |
| Improper Authorization | |
| Uncontrolled Recursion | |
| GHSA-p6gq-j5cr-w38f | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2024-37890 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2025-59471 | |
| Resource Exhaustion | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Link Following | |
| Resource Exhaustion | |
| Resource Exhaustion | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Scripting (XSS) | |
| Algorithmic Complexity | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| CVE-2024-34351 | |
| Uncontrolled Recursion | |
| Allocation of Resources Without Limits or Throttling | |
| GHSA-5j59-xgg2-r9c4 | |
| Improper Handling of URL Encoding (Hex Encoding) | |
| Algorithmic Complexity | |
| Incorrect Authorization | |
| Improper Certificate Validation | |
| GHSA-q4gf-8mx6-v5v3 | |
| Uncontrolled Recursion | |
| Improper Verification of Cryptographic Signature | |
| OS Command Injection | |
| GHSA-w37m-7fhw-fmv9 | |
| Directory Traversal | |
| Interpretation Conflict | |
| Resource Exhaustion | |
| Arbitrary Code Injection | |
| Improper Handling of Exceptional Conditions | |
| Resource Exhaustion | |
| Inefficient Regular Expression Complexity | |
| Allocation of Resources Without Limits or Throttling | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-33806 | |
| Improper Input Validation | |
| Directory Traversal | |
| OS Command Injection | |
| Directory Traversal | |
| CVE-2026-1526 | |
| CVE-2026-32280 | |
| Allocation of Resources Without Limits or Throttling | |
| Server-Side Request Forgery (SSRF) | |
| Uncaught Exception | |
| XML Injection | |
| Improper Verification of Cryptographic Signature | |
| Open Redirect | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-9697 | |
| Direct Request ('Forced Browsing') | |
| Cross-site Scripting (XSS) | |
| Information Exposure | |
| Improper Input Validation | |
| CVE-2026-12143 | |
| Overly Permissive Cross-domain Whitelist | |
| CVE-2026-6322 | |
| Directory Traversal | |
| CVE-2025-1302 | |
| Improper Certificate Validation | |
| Exposure of Resource to Wrong Sphere | |
| CVE-2025-22868 | |
| Arbitrary Code Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Symlink Following | |
| HTTP Request Smuggling | |
| Race Condition | |
| GHSA-mwv6-3258-q52c | |
| XML Injection | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Directory Traversal | |
| Incorrect Execution-Assigned Permissions | |
| Cross-site Scripting (XSS) | |
| CVE-2026-6321 | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Acceptance of Extraneous Untrusted Data With Trusted Data | |
| Resource Exhaustion | |
| CVE-2026-2391 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improper Authorization | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| CVE-2025-48985 | |
| Reversible One-Way Hash | |
| Uncontrolled Recursion | |
| GHSA-5c6j-r48x-rmvq | |
| Incorrect Authorization | |
| Authentication Bypass | |
| Use of a Broken or Risky Cryptographic Algorithm | |
| CVE-2024-41110 | |
| Out-of-Bounds | |
| Missing Authorization | |
| Deserialization of Untrusted Data | |
| GHSA-9qr9-h5gf-34mp | |
| Improper Authorization | |
| CVE-2026-39821 | |
| CVE-2025-68121 | |
| Missing Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| Improper Certificate Validation | |
| Directory Traversal | |
| CVE-2026-9277 | |
| CVE-2026-27143 | |
| CVE-2026-46595 | |
| Integer Overflow or Wraparound | |
| CVE-2024-21534 | |
| CVE-2023-45288 | |
| Information Exposure | |
| Incorrect Authorization | |
| CVE-2025-31125 | |