<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-16 on ZAP</title>
    <link>/alerttags/cwe-16/</link>
    <description>Recent content in CWE-16 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-16/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Deprecated Feature Policy Header Set</title>
      <link>/docs/alerts/10063-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10063-2/</guid>
      <description>&lt;p&gt;The header has now been renamed to Permissions-Policy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GET for POST</title>
      <link>/docs/alerts/10058/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10058/</guid>
      <description>&lt;p&gt;A request that was originally observed as a POST was also accepted as a GET. This issue does not represent a security weakness unto itself, however, it may facilitate simplification of other attacks. For example if the original POST is subject to Cross-Site Scripting (XSS), then this finding may indicate that a simplified (GET based) XSS may also be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL Circular Type Reference</title>
      <link>/docs/alerts/50007-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/50007-3/</guid>
      <description>&lt;p&gt;A circular reference was detected in the GraphQL schema, where object types reference each other in a cycle. This can be exploited by attackers to craft deeply recursive queries, potentially leading to Denial of Service (DoS) conditions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL Endpoint Supports Introspection</title>
      <link>/docs/alerts/50007-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/50007-1/</guid>
      <description>&lt;p&gt;The GraphQL endpoint has Introspection enabled. Introspection allows clients to query the schema and retrieve detailed information about the fields, types, inputs, etc. supported by the GraphQL endpoint. This may be valuable to an attacker, as it could enable them to craft more targeted queries.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
