Go

Pages44

Integer overflow in allocation size calculations

Integer overflow in allocation size calculations

Binding to all network interfaces

Binding network interfaces beyond the service's intended access scope

Plaintext logging of sensitive information

Plaintext logging of sensitive information

Use of a fixed OAuth2 state value

Use of a fixed OAuth2 state value

Sensitive cookie set without the Secure flag

Sensitive cookie set without the Secure flag

Cookie exposure without HttpOnly

Script access to sensitive cookies without HttpOnly

Denial of service from decompression bombs

Unbounded resource consumption during decompression

TLS certificate verification disabled

TLS certificate verification disabled

Information exposure through directory listings

File and information exposure through directory listings

Email header and body injection

Email header and body injection

Cleartext transmission of sensitive information

Cleartext transmission of sensitive information

Incorrect integer conversions

Incorrect integer conversions

An SSLv3 minimum-version setting

An SSLv3 minimum-version setting

Insecure temporary file creation

Insecure temporary file creation

Weak or risky TLS cipher suites

Weak or risky TLS cipher suites

Log injection

Log injection

Weak password hashing with MD5

Use of a broken or risky cryptographic algorithm

Parsing user-controlled JWTs without signature verification

Parsing user-controlled JWTs without signature verification

Review the minimum TLS version

Review the minimum TLS version

Open redirect

Open redirect

Unsafe password storage or use of fast hashes

Unsafe password storage or use of fast hashes

Exposed pprof debugging endpoints

Exposed pprof debugging endpoints

Bypassing incomplete regular-expression validation

Bypassing incomplete regular-expression validation

Bit shifts at or beyond the integer type width

Bit shifts at or beyond the integer type width

SQL injection

SQL injection

Key exchange without server identity verification

Key exchange without server identity verification

Server-side request forgery (SSRF)

Server-side request forgery (SSRF)

Stack trace exposure

Stack trace exposure

Cross-site scripting (XSS)

Cross-site scripting (XSS)

Cross-site scripting (XSS)

Cross-site scripting (XSS)

Excessive memory allocation from user input

Excessive memory allocation from user input

Cross-site scripting (XSS)

Cross-site scripting (XSS)

Cross-site scripting (XSS)

Cross-site scripting (XSS)

Cross-site scripting (XSS)

Cross-site scripting

Unsafe symbolic links during archive extraction

Unsafe symbolic-link creation during archive extraction

Use of the unsafe package

Use of the unsafe package

Use of weak cryptographic algorithms

Use of weak cryptographic algorithms

Cryptographically weak random generation

Cryptographically weak random generation

Weak RSA key length

Weak RSA key length

XPath injection

XPath injection

XML external entity (XXE) vulnerability

XML external entity (XXE) vulnerability

Zip Slip archive path traversal

Zip Slip archive path traversal

Operating system command injection

Operating system command injection

Path traversal

Path traversal