Skip to content

Mitigate

Python pickle / dill on untrusted input

April 25, 2026

PyYAML `yaml.load` without a safe Loader

April 25, 2026

Java ObjectInputStream and friends

April 25, 2026

XML external entities (XXE) — parser defaults

April 25, 2026

JWT — `alg: none` and algorithm confusion

April 25, 2026

JavaScript `eval()` / `new Function()` on untrusted input

April 25, 2026

Disabled TLS verification — `verify=False` and friends

April 25, 2026

Prototype pollution — `merge`, `assign`, and friends

April 25, 2026