| Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | |
| External Control of File Name or Path | |
| Improper Neutralization | |
| Allocation of Resources Without Limits or Throttling | |
| External Control of File Name or Path | |
| Information Exposure Through Caching | |
| CRLF Injection | |
| Information Exposure Through Caching | |
| Key Exchange without Entity Authentication | |
| HTTP Request Smuggling | |
| Incorrect Implementation of Authentication Algorithm | |
| Resource Exhaustion | |
| Unchecked Input for Loop Condition | |
| Allocation of Resources Without Limits or Throttling | |
| Inefficient Regular Expression Complexity | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Validation of Syntactic Correctness of Input | |
| Improper Verification of Source of a Communication Channel | |
| CRLF Injection | |
| Improper Certificate Validation | |
| Incorrect Execution-Assigned Permissions | |
| Authentication Bypass | |
| Improper Null Termination | |
| Allocation of Resources Without Limits or Throttling | |
| Inefficient Regular Expression Complexity | |
| Incorrect Use of Privileged APIs | |
| Inefficient Regular Expression Complexity | |
| Information Exposure | |
| Authentication Bypass | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Validation of Syntactic Correctness of Input | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Certificate Validation | |
| Improper Verification of Source of a Communication Channel | |