Python
Pages69
Binding to all network interfaces
Check that binding to every interface matches the service’s intended access scope.
Use of weak cryptography
Review weak cryptography and use encryption with key management and integrity verification.
Broken user authentication
Protect accounts through password verification, login-attempt limits, and session management.
Clear-text logging of sensitive data
Remove or redact sensitive values such as passwords and tokens from logs.
Clear-text storage of sensitive data
Clear-text storage of sensitive data
Python code injection
Python code injection through eval and exec
Command injection
Command injection
Cross-site request forgery
Cross-site request forgery (CSRF)
Debug and testing modes enabled
Debug or testing mode enabled in a production Python web application
Missing limits on Django login attempts
Missing limits on Django login attempts
Security decisions based on DNS lookup results
Security decisions based on DNS lookup results
Empty exception handler
Empty exception handler
Exception message exposure
Exception message exposure
Overly permissive FastAPI CORS settings
Overly permissive FastAPI CORS settings
Format string injection
External input used as a format string
Overly broad exception handling
Overly broad exception handling
Deserialization of untrusted data
Deserialization of untrusted data
Hardcoded credentials
Credentials embedded in source code
Hardcoded encryption IV
Hardcoded initialization vector in encryption
Hardcoded cryptographic keys
Cryptographic keys embedded in source code
Hardcoded secrets
Secrets embedded in application code
HTTP response splitting
HTTP response splitting
Sensitive cookies without HttpOnly
Sensitive cookies without the HttpOnly flag
Sensitive cookies without Secure
Sensitive cookies without the Secure attribute
Improper certificate validation
Improper certificate validation
Improper handling of permissions
Improper handling of insufficient permissions or privileges
Incomplete URL validation
Incomplete URL validation
Excessive file permissions
Insecure file permissions
Insecure temporary file creation
Insecure temporary file creation
Insufficient cryptographic key size
Insufficient cryptographic key size
Jinja autoescaping is disabled
Jinja autoescaping is disabled
Jinja server-side template injection (SSTI)
Jinja server-side template injection
JWT signature verification is disabled
JWT signature verification is disabled
LDAP injection
LDAP injection
Unsafe lxml XMLParser options
Disable external entities and unnecessary parser features when handling untrusted XML.
Dereferencing a value before checking for None
Dereferencing a value before checking for None
NoSQL injection
Prevent user input from changing the structure or operators of a NoSQL query.
NumPy fixed-width integer overflow
NumPy fixed-width integer overflow
Open redirect
Validate redirect hosts and schemes to prevent unintended redirects to external sites.
Origin validation errors
Apply appropriate origin validation and CSRF protection to requests whose credentials are sent automatically by the browser.
PAM authorization bypass
Check account status and access policies after successful PAM authentication.
Path traversal
Prevent user-controlled paths from reaching files outside the intended base directory.
Assigning an external array reference directly to a private field
Assigning an external array reference directly to a private field
Returning a private array directly
Returning a private array directly
Regular expression denial of service
Regular expression denial of service (ReDoS)
Secure encryption modes and padding
Use encryption modes and padding appropriate to each algorithm.
Sensitive information in comments
Sensitive information is included in comments.
Server information exposure
Unnecessary internal server information is exposed to clients.
Request data stored in class variables
User-specific request data is stored in class variables.
SQL injection
SQL injection