| Class name | Summary |
|---|---|
| BLA1:2025 - Action Limit Overrun (ALO) | Overrun Limit of Idempotent Operations arises when unsynchronized concurrent requests exploit a TOCTOU gap to bypass single-use checks and repeatedly execute operations like coupon redemptions or refunds. |
| BLA2:2025 - Concurrent workflow order bypass (CWOB) | Workflow Order Bypass is a race-condition attack that runs a workflow’s final step before its required prior steps complete, either across distributed commands or within unguarded internal sub-states. |
| BLA3:2025 - Object state manipulations (OSM) | Object state manipulation flaws occur when APIs bind unfiltered user input into internal objects without validating fields or types, allowing attackers to override protected properties, such as roles or permissions. |
| BLA4:2025 - Malicious Logic Loop (MLL) | APIs lacking proper gating, loop exit checks, input validation, or recursion limits can be exploited to trigger hidden routines and exhaust resources, leading to service crashes, financial loss, or denial of service. |
| BLA5:2025 - Artifact Lifetime Exploitation (ALE) | Abuse of one-time or short-lived resources, like tokens, sessions, or temporary files left valid beyond their intended lifecycle, lets attackers replay stale artifacts to access sensitive operations or data. |
| BLA6:2025 - Missing Transition Validation (MTV) | Transition validation flaws occur when APIs defer or omit essential checks in multi-step state workflows, letting attackers call later endpoints and enabling unauthorized workflows. |
| BLA7:2025 - Resource Quota Violation (RQV) | Without proper rate limits, business endpoints triggering heavy operations can be abused to exhaust resources, degrade services, or cause financial harm in AI systems where one user’s token overuse can DoS others. |
| BLA8:2025 - Internal State Disclosure (ISD) | When systems show different messages, codes, visuals, delays for valid vs invalid inputs they leak internal states, enabling attackers to lay groundwork for targeted intrusion or fraud. |
| BLA9:2025 - Broken Access Control (BAC) | Flawed or missing role and permission checks in critical workflows let attackers spoof roles, bypass controls, and execute unauthorized actions, causing privilege escalation and data integrity breaches. |
| BLA10:2025 - Shadow Function Abuse (SFA) | Shadow functions are unprotected hidden features in production code, like internal APIs or test utilities, which attackers find via code inspection or discovery tools to bypass security and access restricted data. |
| 1 Of the analyzed security issues on Github. Referer to the Methodology section for further information. |
Project Leader
Project Leader