2026
Last updated: Oct 3, 2026
October
Release 40
-
(ASPM) Authentication can now be configured on any web application environment: You can now set up authentication for any web application environment. Previously, the platform restricted authentication to specific environment categories.
-
(ASPM) VLAI severity is now shown across all testing techniques: The platform now displays the Vulnerability Language AI (VLAI) severity score for all findings. This score is available for all manual and automated testing techniques.
-
(ASPM) Peer Reviewer Assistant is now available on Essential groups: The Peer Reviewer Assistant is now available on Essential groups. This assistant provides security feedback on code changes. It uses a rule-based engine to give consistent and predictable feedback.
-
(SAST) Laravel endpoint detection is now supported: The SAST scanner can now detect and analyze API endpoints that use the Laravel PHP framework. This increases coverage for PHP applications.
-
(SAST) New rules:
- C Sharp Key Derived Iv Nonce
- C Sharp Predictable Iv Nonce Source
- Dart Predictable Iv Nonce Source
- Elixir Key Derived Iv Nonce
- Elixir Predictable Iv Nonce Source
- Go Key Derived Iv Nonce
- Java Key Derived Iv Nonce
- Java Short Gcm Auth Tag
- Javascript Key Derived Iv Nonce
- Javascript Predictable Iv Nonce Source
- Javascript Short Gcm Auth Tag
- Javascript Webcrypto Short Auth Tag
- Kotlin Key Derived Iv Nonce
- Kotlin Predictable Iv Nonce Source
- Php Key Derived Iv Nonce
- Php Short Gcm Auth Tag
- Python Key Derived Iv Nonce
- Python Short Gcm Auth Tag
- Ruby Short Gcm Auth Tag
- Rust Key Derived Iv Nonce
- Rust Predictable Iv Nonce Source
- Scala Key Derived Iv Nonce
- Scala Predictable Iv Nonce Source
- Scala Short Gcm Auth Tag
- Swift Predictable Iv Nonce Source
- Typescript Key Derived Iv Nonce
- Typescript Predictable Iv Nonce Source
- Typescript Short Gcm Auth Tag
- Typescript Webcrypto Short Auth Tag
-
(SS) New rules:
-
(SS) New validity checks:
-
(Reachability) New rules:
- CVE-2018-20990
- CVE-2019-16728
- CVE-2020-26870
- CVE-2020-35905
- CVE-2020-35916
- CVE-2021-21330
- CVE-2023-49081
- CVE-2023-49082
- CVE-2023-53159
- CVE-2024-27306
- CVE-2024-3568
- CVE-2024-42367
- CVE-2024-58266
- CVE-2024-58378
- CVE-2025-15599
- CVE-2025-26791
- CVE-2025-3777
- CVE-2025-3933
- CVE-2025-6921
- CVE-2025-69226
- CVE-2025-71346
- CVE-2026-0540
- CVE-2026-34513
- CVE-2026-34514
- CVE-2026-34515
- CVE-2026-34518
- CVE-2026-34519
- CVE-2026-41240
- CVE-2026-57438
- GHSA-5w6v-399v-w3cc
- GHSA-mc8h-8q98-g5hr
- GHSA-mjjq-c88q-qhr6
- GHSA-wfpw-mmfh-qq69
- GHSA-xc9x-jj77-9p9j
September
Release 39
-
(ASPM) Group language changes now translate existing content: When you change the content language of a group, the platform translates the existing content of the group. It translates the findings, comments, reattack comments, evidence captions and reports into the selected language. The platform always keeps the untranslated text.
-
(ASPM) Remediation guides are stored and can be regenerated on demand: The platform saves the "How to Fix" guide when it makes the guide for the first time. When you open the vulnerability again, the platform immediately shows the same guide and does not make a new one. If necessary, the Regenerate control makes a new guide.
-
(DB) Elixir SAST weaknesses now have code fix examples: Each weakness that the Elixir SAST scanner can detect has at least one code fix example on db.fluidattacks.com. The examples show a vulnerable snippet and a fixed version for each of the 18 weaknesses.
-
(DB) Kotlin SAST weaknesses now have code fix examples: Each weakness that the Kotlin SAST scanner can detect has at least one code fix example on db.fluidattacks.com.
-
(DB) Rust SAST weaknesses now have code fix examples: Each weakness that the Rust SAST scanner can detect has at least one code fix example on db.fluidattacks.com.
-
(SAST) New rules:
- C Sharp Hardcoded Aead Nonce
- C Sharp Insecure Aes Cipher Mode
- Elixir Hardcoded Aead Nonce
- Elixir Hardcoded Cryptographic Key
- Go Hardcoded Aead Nonce
- Go Insecure Aes Cipher Mode
- Go Predictable Iv Nonce Source
- Java Hardcoded Gcm Nonce
- Java Insecure Aes Cipher Mode
- Java Predictable Iv Nonce Source
- Javascript Hardcoded Aead Nonce
- Kotlin Insecure Aes Cipher Mode
- Php Hardcoded Aead Nonce
- Php Missing Initialization Vector
- Php Predictable Iv Nonce Source
- Python Hardcoded Aead Nonce
- Python Predictable Iv Nonce Source
- Ruby Explicit Ecb Mode
- Ruby Hardcoded Aead Nonce
- Ruby Insecure Aes Cipher Mode
- Ruby Predictable Iv Nonce Source
- Rust Hardcoded Aead Nonce
- Rust Insecure Aes Cipher Mode
- Scala Hardcoded Gcm Nonce
- Scala Insecure Aes Cipher Mode
- Swift Hardcoded Aead Nonce
- Swift Missing Initialization Vector
- Typescript Hardcoded Aead Nonce
-
(SS) New rules:
- Coralogix Api Key
- Coralogix Private Key
- Honeycomb Ingest Api Key
- Honeycomb Management Api Key
- Influxdb Api Token
- Influxdb 3 Api Token
- Loggly Api Token
- Loggly Customer Token
- Logz Io Api Token
- Logz Io Shipping Token
- Midtrans Sandbox Server Key
- Midtrans Server Key
- Onelogin Secret Key
- Opsgenie Api Key
- Pingdom Api Token
- Rollbar Api Token
- Visa Password
- Xendit Secret Key
-
(SS) New validity checks:
-
(Reachability) New rules:
- CVE-2007-3215
- CVE-2012-0796
- CVE-2013-1348
- CVE-2013-1397
- CVE-2013-4752
- CVE-2013-5958
- CVE-2014-2054
- CVE-2015-2308
- CVE-2015-2309
- CVE-2017-1000188
- CVE-2017-16006
- CVE-2017-16224
- CVE-2017-16226
- CVE-2017-20162
- CVE-2018-25110
- CVE-2018-3717
- CVE-2018-6341
- CVE-2019-10761
- CVE-2026-40260
- CVE-2026-41168
- CVE-2026-48155
- CVE-2026-48156
- CVE-2026-59937
- CVE-2026-59938
- CVE-2026-65636
- CVE-2026-66838
- CVE-2026-71852
- CVE-2026-71870
- CVE-2026-84310
- CVE-2026-84311
Release 38
-
(ASPM) Author mailmap search now covers email addresses and aliases: The search bar in the Authors section returns results when the search term matches the author name, the canonical email, or a mapped alias email.
-
(SS) Secrets Scanner now honors group exclusions and severity policy on authenticated runs: On authenticated runs, the Secrets Scanner applies the path exclusions and the severity policy that you configured for the group. Thus, the pipeline configuration cannot override the security decisions that you set in the platform.
-
(SCA) SCA scanner now honors group exclusions and severity policy on authenticated runs: On authenticated runs, the SCA scanner applies the path exclusions and the severity policy that you configured for the group. Thus, the pipeline configuration cannot override the security decisions that you set in the platform.
-
(SAST) SAST scanner now honors group exclusions and severity policy on authenticated runs: On authenticated runs, the SAST scanner applies the path exclusions and the severity policy that you configured for the group. Thus, the pipeline configuration cannot override the security decisions that you set in the platform.
-
(SAST) New rules:
- C Sharp Insecure Cipher Mode
- Dart Pointycastle Explicit Ecb Mode
- Javascript Rsa No Padding
- Php Explicit Ecb Mode
- Python Rsa Legacy Padding
- Typescript Rsa No Padding
- Javascript Rsa Legacy Padding
- Php Rsa Legacy Padding
- Php Rsa No Padding
- Ruby Rsa Legacy Padding
- Ruby Rsa No Padding
- Typescript Rsa Legacy Padding
-
(SS) New rules:
- Customerio App Api Key
- Customerio Track Api Key
- Klaviyo Api Key
- Mailjet Keys
- Resend Api Key
- Vonage Keys
- Wechat App Secret
- Line Channel Access Token
- Nylas Api Key
- Paystack Secret Key
- Paystack Test Secret Key
- Ringcentral Client Secret
- Dwolla Secret Key
- Pagarme Api Key
- Pagarme Test Api Key
- Stripe Webhook Secret
- Wise Api Token
-
(SS) New validity checks:
-
(Reachability) New rules:
- CVE-2009-1523
- CVE-2010-1622
- CVE-2011-2894
- CVE-2012-5055
- CVE-2012-5633
- CVE-2013-4660
- CVE-2013-7452
- CVE-2013-7453
- CVE-2013-7454
- CVE-2014-1829
- CVE-2014-1830
- CVE-2014-6394
- CVE-2014-9772
- CVE-2015-0220
- CVE-2015-1370
- CVE-2015-2296
- CVE-2015-2317
- CVE-2015-8862
- CVE-2015-9235
- CVE-2016-1000232
- CVE-2016-1000236
- CVE-2016-10518
- CVE-2016-10531
- CVE-2016-2512
- CVE-2016-2513
- CVE-2016-9015
Release 37
-
(SS) Secrets Scanner verifies detected secrets against the live provider: The Secrets Scanner checks each detected credential against the API of its provider. Thus, the scanner shows if the credential is live or rotated.
-
(SAST) New rules:
- Rust Hardcoded Rng Seed
- Rust Axum Write Path Traversal
- Rust Grpc Client Insecure Connection
- Rust Zip Slip Path Traversal
- Elixir Dynamodb Nosql Injection
- Elixir Unsafe Dynamic File Inclusion
- Rust Axum Reflected Xss
- Elixir Hardcoded Jwt Secret
- Elixir Sensitive Information In Logs
- Elixir Sensitive Information In Url
- Elixir Ecto Plaintext Storage Of Password
- Elixir Ecto Weak Password Encoding Base64
- Elixir Mongo Nosql Injection
- Elixir User Controlled Connection String
-
(SS) New rules:
-
(DB) Secret detectors now show whether they include a live validity check: In the secrets catalog, you can show only the detectors that can tell if a found credential is active.
-
(Reachability) New rules:
- CVE-2020-5245
- CVE-2020-5398
- CVE-2020-5408
- CVE-2020-7226
- CVE-2020-36320
- CVE-2021-3805
- CVE-2021-3820
- CVE-2021-4264
- CVE-2021-21342
- CVE-2021-21346
- CVE-2021-21350
- CVE-2021-28657
- CVE-2021-33813
- CVE-2021-35515
- CVE-2021-35516
- CVE-2021-35517
- CVE-2021-36090
- CVE-2021-37136
- CVE-2021-37137
- CVE-2021-37533
- CVE-2021-37714
- CVE-2021-39139
- CVE-2021-39140
- CVE-2021-39144
- CVE-2021-39146
- CVE-2021-39147
- CVE-2021-39148
- CVE-2021-39149
- CVE-2021-39150
- CVE-2021-39151
- CVE-2021-39153
- CVE-2021-39154
- CVE-2021-39227
- CVE-2021-40690
- CVE-2021-43309
- CVE-2021-43859
- CVE-2021-43861
- CVE-2022-0144
- CVE-2022-0355
- CVE-2022-0654
- CVE-2022-0722
- CVE-2022-1471
- CVE-2022-1929
- CVE-2022-2596
- CVE-2022-3171
- CVE-2022-3509
- CVE-2022-21144
- CVE-2022-21213
- CVE-2022-21222
- CVE-2022-21227
- CVE-2022-21680
- CVE-2022-21681
- CVE-2022-22143
- CVE-2022-23457
- CVE-2022-23514
- CVE-2022-23517
- CVE-2022-24836
- CVE-2022-24863
- CVE-2022-25645
- CVE-2022-25758
- CVE-2022-25851
- CVE-2022-25852
- CVE-2022-25857
- CVE-2022-25878
- CVE-2022-25885
- CVE-2022-25892
- CVE-2022-25927
- CVE-2022-25967
- CVE-2022-29167
- CVE-2022-29181
- CVE-2022-30122
- CVE-2022-30126
- CVE-2022-30973
- CVE-2022-31159
- CVE-2022-32210
- CVE-2022-37620
- CVE-2022-38749
- CVE-2022-38750
- CVE-2022-38751
- CVE-2022-39381
- CVE-2022-41727
- CVE-2022-44570
- CVE-2023-0163
- CVE-2023-2251
- CVE-2023-4863
- CVE-2023-6753
- CVE-2023-22467
- CVE-2023-22794
- CVE-2023-22799
- CVE-2023-23630
- CVE-2023-24537
- CVE-2023-24807
- CVE-2023-25166
- CVE-2023-25345
- CVE-2023-25653
- CVE-2023-26111
- CVE-2023-26132
- CVE-2023-26920
- CVE-2023-27530
- CVE-2023-27539
- CVE-2023-29331
- CVE-2023-29407
- CVE-2023-29408
- CVE-2023-30533
- CVE-2023-36414
- CVE-2023-45141
- CVE-2023-45142
- CVE-2023-52323
- CVE-2024-0056
- CVE-2024-1455
- CVE-2024-3571
- CVE-2024-3651
- CVE-2024-3772
- CVE-2024-6104
- CVE-2024-10940
- CVE-2024-12911
- CVE-2024-21272
- CVE-2024-21319
- CVE-2024-21506
- CVE-2024-21664
- CVE-2024-23334
- CVE-2024-23342
- CVE-2024-24786
- CVE-2024-24792
- CVE-2024-26130
- CVE-2024-27134
- CVE-2024-27318
- CVE-2024-27454
- CVE-2024-27929
- CVE-2024-28088
- CVE-2024-28102
- CVE-2024-28219
- CVE-2024-29857
- CVE-2024-29992
- CVE-2024-34069
- CVE-2024-34072
- CVE-2024-37052
- CVE-2024-37053
- CVE-2024-37054
- CVE-2024-37055
- CVE-2024-37056
- CVE-2024-37057
- CVE-2024-37058
- CVE-2024-37059
- CVE-2024-37298
- CVE-2024-37568
- CVE-2024-38095
- CVE-2024-39677
- CVE-2024-41131
- CVE-2024-43398
- CVE-2024-45338
- CVE-2024-45339
- CVE-2024-47887
- CVE-2024-47888
- CVE-2024-48510
- CVE-2024-51736
- CVE-2024-56365
- CVE-2025-8959
- CVE-2025-22869
- CVE-2025-24883
- CVE-2025-25293
- CVE-2025-27513
- CVE-2025-27598
- CVE-2025-27610
- CVE-2025-27788
- CVE-2025-30204
- CVE-2025-46727
- CVE-2025-47908
- CVE-2025-48882
- CVE-2025-49007
- CVE-2025-58190
- CVE-2025-61726
- CVE-2025-65637
- CVE-2026-17106
- CVE-2026-27138
- CVE-2026-32935
- CVE-2026-40863
- CVE-2026-40902
- CVE-2026-44167
- CVE-2026-45067
Release 36
-
(SCA) Yarn, pnpm, and Bun lockfiles now parsed for SCA: The SCA engine added deterministic lockfile parsers for Yarn, pnpm, and Bun. Thus, the engine covers the dependencies of these package managers, and not only of npm.
-
(ASPM) Vulnerability origin column added to the technical Excel report: The Excel technical report includes an Origin column. For each vulnerability, this column shows Injected or Inherited.
-
(ASPM) Fraud Risk View: Organizations can see the fraud patterns that their open vulnerabilities enable. For each category, the view shows the exposure level and the vulnerabilities by severity. Organizations can also escalate to the responsible contact.
-
(MCP) Secure Context: Developers can load the security rules of Fluid Attacks into each MCP-compatible AI coding agent. Thus, the agent gives them guidance while they write code.
-
(DB) Campaigns browsable in the rules catalog: The rules catalog at db.fluidattacks.com shows the security rule campaigns, and you can filter the catalog by campaign.
-
(SAST) New rules:
- Rust Actix Cors Permissive Policy
- Rust Delete Path Traversal
- Rust Httponly Cookie Flag Not Set
- Rust Insecure Dsa Functions Use
- Rust Insecure File Permissions
- Rust Insecure Samesite Cookie Attribute
- Rust Jwt Lack Of Expiration
- Rust Mongodb Nosql Injection
- Rust Sensitive Persistent Cookie
- Rust Tempfile Unencrypted Sensitive Information
- Rust Weak Prng Cookie Token
- Rust Websocket Client Insecure Connection
-
(SS) New rules:
- Browserstack Access Key
- Browserstack Hub Url Access Key
- Browserstack Yml Config Access Key
- Cloudflare Legacy Api Token
- Codecov Personal Access Token
- Codecov Upload Token
- Coveralls Config Repo Token
- Coveralls Personal Api Token
- Coveralls Repo Token
- Crates Io Api Token
- Octopus Deploy Api Key
- Teamcity Token
-
(SS) New validity checks:
- Bird API Key
- Discord Webhook Url
- Harness Api Key
- Intercom Api Key
- Jina Api Key
- Launchdarkly Api Key
- Linear Api Token
- Lob Api Key
- Mailgun Api Key
- Mandrill API Key
- Mapbox Secret Token
- Mercado Pago Access Token
- Messagebird Api Key
- Mistral Api Key
- Netlify Access Token
- Netlify Access Token Legacy
- Newrelic Api Key
- Nuget Api Key
- Nvidia Api Key
- Plivo API Token
- Postmark Account API Token
- Postmark API Token
- PubNub Access Key
-
(Reachability) New rules:
- CVE-2015-3542
- CVE-2016-2402
- CVE-2016-3090
- CVE-2016-3092
- CVE-2016-3674
- CVE-2016-5725
- CVE-2017-5656
- CVE-2017-7957
- CVE-2017-12624
- CVE-2017-12972
- CVE-2017-12974
- CVE-2017-18640
- CVE-2018-1320
- CVE-2018-1324
- CVE-2018-11039
- CVE-2018-11040
- CVE-2018-11771
- CVE-2018-17197
- CVE-2018-1000632
- CVE-2018-1002202
- CVE-2019-0231
- CVE-2019-1258
- CVE-2019-10088
- CVE-2019-10093
- CVE-2019-10094
- CVE-2020-1950
- CVE-2020-1951
- CVE-2020-4038
- CVE-2020-5313
- CVE-2020-7661
- CVE-2020-7689
- CVE-2020-7733
- CVE-2020-7751
- CVE-2020-7752
- CVE-2020-7753
- CVE-2020-7754
- CVE-2020-7765
- CVE-2020-7768
- CVE-2020-7787
- CVE-2020-7792
- CVE-2020-7793
- CVE-2020-8130
- CVE-2020-8141
- CVE-2020-8175
- CVE-2020-8237
- CVE-2020-11002
- CVE-2020-11612
- CVE-2020-11988
- CVE-2020-13692
- CVE-2020-15225
- CVE-2020-25658
- CVE-2020-25659
- CVE-2020-26217
- CVE-2020-26259
- CVE-2020-26289
- CVE-2020-26291
- CVE-2020-26302
- CVE-2020-26311
- CVE-2020-28168
- CVE-2020-28477
- CVE-2020-28478
- CVE-2020-28496
- CVE-2020-28948
- CVE-2020-28949
- CVE-2020-29651
- CVE-2020-35653
- CVE-2020-35654
- CVE-2020-36193
- CVE-2020-36242
- CVE-2021-3757
- CVE-2021-3777
- CVE-2021-3795
- CVE-2021-3828
- CVE-2021-20270
- CVE-2021-21315
- CVE-2021-21388
- CVE-2021-22904
- CVE-2021-23326
- CVE-2021-23353
- CVE-2021-23413
- CVE-2021-23437
- CVE-2021-23460
- CVE-2021-23490
- CVE-2021-25287
- CVE-2021-25288
- CVE-2021-25290
- CVE-2021-25293
- CVE-2021-27292
- CVE-2021-27516
- CVE-2021-27921
- CVE-2021-27922
- CVE-2021-28092
- CVE-2021-28458
- CVE-2021-28676
- CVE-2021-28678
- CVE-2021-28965
- CVE-2021-29059
- CVE-2021-29443
- CVE-2021-29444
- CVE-2021-29445
- CVE-2021-29446
- CVE-2021-29489
- CVE-2021-30130
- CVE-2021-32012
- CVE-2021-32013
- CVE-2021-32014
- CVE-2021-32803
- CVE-2021-33502
- CVE-2021-33571
- CVE-2021-33587
- CVE-2021-33880
- CVE-2021-35065
- CVE-2021-37712
- CVE-2021-41098
- CVE-2021-41355
- CVE-2021-42771
- CVE-2021-43854
- CVE-2022-21712
- CVE-2022-24302
- CVE-2022-24303
- CVE-2022-24775
- CVE-2022-24894
- CVE-2022-29217
- CVE-2022-29248
- CVE-2022-36359
- CVE-2022-39280
- CVE-2022-40023
- CVE-2022-40896
- CVE-2022-40898
- CVE-2022-41343
- CVE-2022-45198
- CVE-2023-27560
- CVE-2023-28859
- CVE-2023-29530
- CVE-2023-30608
- CVE-2023-32786
- CVE-2023-33733
- CVE-2023-33976
- CVE-2023-36189
- CVE-2023-36464
- CVE-2023-36810
- CVE-2023-37260
- CVE-2023-38325
- CVE-2023-39441
- CVE-2023-43804
- CVE-2023-46250
- CVE-2023-49316
- CVE-2023-52892
- CVE-2024-27354
- CVE-2024-27355
- CVE-2024-45048
- CVE-2024-45290
- CVE-2024-45293
- CVE-2024-47873
- CVE-2024-48917
- CVE-2024-51058
- CVE-2026-43671
August
Release 35
-
(ASPM) Stop a streaming AI Agent response: Users can stop a response of the AI Agent from the chat interface before the response is complete.
-
(SAST) New rules:
- Rust Absolute Path Traversal
- Rust Diesel Weak Password Encoding Base64
- Rust Ssrf Reqwest Awc Client
- Rust Actix Open Redirect
- Rust Log Macro Injection
- Rust Secure Cookie Flag Not Set
- Rust Sensitive Information In Http Response
- Rust Uncontrolled Memory Allocation
- Rust Arithmetic Integer Overflow
- Rust Unsafe X Frame Options Header
- Rust Disabled Hsts Max Age
- Rust Hardcoded Salt In Bcrypt
- Rust Insecure Content Security Policy
- Rust Session Trust Boundary Violation
-
(SS) New rules:
- K3s Token
- Cloudinary Api Key
- Ovh Shared Secret
- Tencent Secret Key
- Codeclimate Api Token
- Codeclimate Repo Token
- Codeclimate Test Reporter Token
- Azure Iot Hub Connection String
- Sauce Labs Access Key
- Azure Communication Services Connection String
- Azure Event Hub Connection String
- Portainer Api Key
- Proxmox Api Token
- Cloudflare Account Api Token
-
(SS) New validity checks:
-
(Reachability) New rules:
- CVE-2006-5734
- CVE-2012-3444
- CVE-2014-0012
- CVE-2014-0050
- CVE-2014-0225
- CVE-2014-0480
- CVE-2014-1402
- CVE-2014-5244
- CVE-2014-7191
- CVE-2014-9970
- CVE-2014-10064
- CVE-2015-2156
- CVE-2015-5144
- CVE-2015-5145
- CVE-2015-5262
- CVE-2015-8315
- CVE-2015-8851
- CVE-2015-8854
- CVE-2015-8855
- CVE-2015-8858
- CVE-2015-8860
- CVE-2016-2175
- CVE-2016-2515
- CVE-2016-4055
- CVE-2016-10539
- CVE-2016-10540
- CVE-2016-10707
- CVE-2016-1000341
- CVE-2016-1000345
- CVE-2017-5223
- CVE-2017-11879
- CVE-2017-12852
- CVE-2017-16026
- CVE-2017-16030
- CVE-2017-16099
- CVE-2017-16113
- CVE-2017-16116
- CVE-2017-16117
- CVE-2017-16119
- CVE-2017-16129
- CVE-2017-16136
- CVE-2017-16138
- CVE-2017-18077
- CVE-2017-1000048
- CVE-2017-1000189
- CVE-2018-3719
- CVE-2018-3728
- CVE-2018-3737
- CVE-2018-3738
- CVE-2018-10903
- CVE-2018-11798
- CVE-2018-16469
- CVE-2018-16472
- CVE-2018-16490
- CVE-2018-18074
- CVE-2018-19277
- CVE-2018-19296
- CVE-2018-20744
- CVE-2018-20834
- CVE-2018-20835
- CVE-2018-25079
- CVE-2018-1000201
- CVE-2018-1000210
- CVE-2018-1000808
- CVE-2018-1002204
- CVE-2018-1002205
- CVE-2018-1002208
- CVE-2019-0542
- CVE-2019-10768
- CVE-2019-11254
- CVE-2019-11840
- CVE-2019-11841
- CVE-2019-12331
- CVE-2019-13173
- CVE-2019-14232
- CVE-2019-14233
- CVE-2019-14235
- CVE-2019-14322
- CVE-2019-14751
- CVE-2019-14853
- CVE-2019-15138
- CVE-2019-16865
- CVE-2019-16892
- CVE-2019-18888
- CVE-2019-20920
- CVE-2019-20922
- CVE-2019-1010083
- CVE-2020-8911
- CVE-2020-9283
- CVE-2020-10378
- CVE-2020-10379
- CVE-2020-10994
- CVE-2020-13625
- CVE-2020-13757
- CVE-2020-14040
- CVE-2020-14966
- CVE-2020-15094
- CVE-2020-15256
- CVE-2020-25614
- CVE-2020-26160
- CVE-2020-26245
- CVE-2020-28483
- CVE-2020-29652
- CVE-2021-4235
- CVE-2021-31402
- CVE-2021-33194
- CVE-2022-3064
- CVE-2022-21221
- CVE-2022-21223
- CVE-2022-21698
- CVE-2022-24440
- CVE-2022-24675
- CVE-2022-25765
- CVE-2022-27191
- CVE-2022-28948
- CVE-2022-29526
- CVE-2022-30321
- CVE-2022-30322
- CVE-2022-30323
- CVE-2022-31163
- CVE-2022-32149
- CVE-2022-41720
- CVE-2022-45047
- CVE-2023-26154
- CVE-2023-39137
- CVE-2025-49655
- CVE-2026-41706
- CVE-2026-47698
- CVE-2026-53510
- CVE-2026-54133
- CVE-2026-54603
- CVE-2026-73625
- CVE-2026-73649
- GHSA-9w56-46f6-3qhx
Release 34
-
(SS) New rules:
-
(SS) New validity checks:
- Airtable Personal Access Token
- Aiven Api Key
- Assemblyai Api Key
- Beamer API Token
- Buildkite API Token
- CircleCI Personal API Token
- Codacy Project Token
- Cohere Api Key
- Contentful Personal Access Token
- Deepgram Api Key
- DeepSeek API Key
- Deno Deploy Org Access Token
- Deno Deploy Personal Access Token
- Duffel API Token
- Fastly API Token
- Figma Personal Access Token
- FrameIO API Token
- GoCardless API Token
- Groq API Key
- Infura Api Key
- Railway Account Api Token
- Railway Project Api Token
-
(SAST) New rules:
- Rust Diesel Sqlx Connection String Injection
- Rust Hardcoded Jwt Secret
- Rust User Controlled Connection String
- Rust Actix Static Dir Exposed
- Rust Insecure Cipher Algorithm
- Rust Insecure Hash Algorithm
- Rust Diesel Sqlx Empty Password
- Rust Diesel Sqlx Hardcoded Password
- Rust Insufficient Bcrypt Cost
- Rust Redis Mongo Hardcoded Password
-
(Reachability) New rules:
- CVE-2019-18887
- CVE-2020-7660
- CVE-2020-13822
- CVE-2020-36604
- CVE-2021-34551
- CVE-2022-21223
- CVE-2022-24066
- CVE-2022-24440
- CVE-2022-24828
- CVE-2022-25765
- CVE-2022-25898
- CVE-2022-25912
- CVE-2022-31163
- CVE-2022-39299
- CVE-2022-43441
- CVE-2022-45047
- CVE-2023-37460
- CVE-2023-49803
- CVE-2024-0243
- CVE-2024-38999
- CVE-2024-53899
- CVE-2024-53908
- CVE-2025-13204
- CVE-2025-25975
- CVE-2025-25977
- CVE-2025-49655
- CVE-2025-57353
- CVE-2025-60542
- CVE-2025-61385
- CVE-2025-68154
- CVE-2025-69662
- CVE-2026-1287
- CVE-2026-1312
- CVE-2026-1615
- CVE-2026-4601
- CVE-2026-5598
- CVE-2026-6951
- CVE-2026-12075
- CVE-2026-12481
- CVE-2026-23527
- CVE-2026-23949
- CVE-2026-27459
- CVE-2026-29091
- CVE-2026-32313
- CVE-2026-33468
- CVE-2026-34771
- CVE-2026-39356
- CVE-2026-39983
- CVE-2026-40897
- CVE-2026-41706
- CVE-2026-41720
- CVE-2026-42215
- CVE-2026-42284
- CVE-2026-44001
- CVE-2026-45804
- CVE-2026-46681
- CVE-2026-47698
- CVE-2026-53510
- CVE-2026-54133
- CVE-2026-54603
- CVE-2026-54653
- CVE-2026-55415
- CVE-2026-59197
- CVE-2026-59199
- CVE-2026-67323
- CVE-2026-73625
- CVE-2026-73649
- CVE-2026-76220
- GHSA-9w56-46f6-3qhx
Release 33
-
(DAST-WEB) Web and SSL findings reported as Web DAST: The platform classifies the findings of the active scanner for web and SSL checks as Web DAST findings.
-
(DAST-API) API findings reported as API DAST: The platform classifies the findings of the active scanner for API checks as API DAST findings.
-
(ASPM) Per-vulnerability justifications supported in verification requests: In a vulnerability verification request, you can give a justification for each vulnerability.
-
(IDE Plugin) Automated fixes for Composer dependencies: Developers can request a verified fix for a vulnerable PHP Composer dependency directly from the VS Code extension.
-
(DB) Rules catalog labels Web DAST and API DAST: The catalog identifies each applicable rule as Web DAST or API DAST.
-
(SAST) New rules:
- Python Django Log Injection
- Python Fastapi Log Injection
- Python Starlette Log Injection
- Python Flask User Sdk Configurations
- Python Use Of Insecure Randomness
- Python Django User Sdk Configurations
- Rust Jwt Signature Verification Disabled
- Rust Sensitive Information In Url
- Rust Jwt Sensitive Information Exposure
- Rust Diesel Plaintext Storage Of Password
- Rust Actix Insecure Http Bind
- Rust Command Argument Injection
-
(Reachability) New rules:
- CVE-2015-5254
- CVE-2016-7051
- CVE-2016-10033
- CVE-2016-10045
- CVE-2018-17057
- CVE-2018-1000544
- CVE-2019-10910
- CVE-2019-10913
- CVE-2020-5529
- CVE-2020-14001
- CVE-2020-28052
- CVE-2020-36326
- CVE-2021-3838
- CVE-2021-22573
- CVE-2021-28834
- CVE-2021-32708
- CVE-2021-38561
- CVE-2021-43608
- CVE-2021-46743
- CVE-2022-24720
- CVE-2022-28368
- CVE-2023-22727
- CVE-2023-35169
- CVE-2024-6257
- CVE-2024-27304
- CVE-2024-43498
- CVE-2025-2828
- CVE-2025-25291
- CVE-2025-25292
- CVE-2026-34084
- CVE-2026-45034
- CVE-2026-47304
- CVE-2026-55599
- CVE-2026-63209
- CVE-2026-69240
- CVE-2026-71851
- GHSA-7jwh-3vrq-q3m8
-
(SS) New validity checks:
Release 32
-
(ASPM) Export Design Map threat matches to Excel: In the Design Map, the Threat Matches tab has an export button. This button downloads the current threat match results as an XLSX file.
-
(IDE Plugin) Composer companion files uploaded for SCA fixes: When the IDE extension asks for SCA fix suggestions, it includes
composer.jsonandcomposer.lock. Thus, the extension supports fixes for PHP Composer projects. -
(DB) Reachability capability section in vulnerability detail: The vulnerability page on db.fluidattacks.com has a Reachability Capability section. The reachability filter supports three states: supported, not supported, and impossible.
-
(SCA) Runtime CVE detection narrowed to deployment-bound signals: Runtime CVE detection no longer runs for .NET, Node.js/Bun, or Python. For Ruby, it runs only when a
Procfilesignals a Heroku deployment. Release 25 announced detection from the Ruby.gemspecrequired_ruby_versionfield, but this field also no longer starts the detection. These manifest fields declare only compatibility, not what you actually deploy. Thus, a CVE from these fields can be a vulnerability that does not apply. For the full information about each runtime, see the Runtimes page. -
(Reachability) New rules:
-
(SS) New rules:
-
(SS) New validity checks:
-
(SAST) New rules:
July
Release 31
-
(ASPM) Peer Reviewer for GitHub: The platform automatically adds security findings as comments on GitHub pull requests. You can configure this feature directly from the integrations page of the platform.
-
(Docs) Support response SLA reduced to 8 hours: The maximum initial response time changed from 16 to 8 business hours.
-
(API) API included in availability SLA: The availability SLA explicitly covers the platform API, and not only the web application.
-
(SAST) New rules:
-
(Reachability) New rules:
- CVE-2013-7285
- CVE-2016-3720
- CVE-2017-1000487
- CVE-2017-18342
- CVE-2019-10173
- CVE-2019-13990
- CVE-2019-14859
- CVE-2019-20477
- CVE-2019-7164
- CVE-2019-7548
- CVE-2020-10683
- CVE-2020-14343
- CVE-2020-1747
- CVE-2020-7471
- CVE-2021-23926
- CVE-2021-34552
- CVE-2021-35042
- CVE-2021-43090
- CVE-2021-43113
- CVE-2022-21797
- CVE-2022-23640
- CVE-2022-24065
- CVE-2022-24439
- CVE-2022-25168
- CVE-2022-26612
- CVE-2022-28346
- CVE-2022-28347
- CVE-2022-34265
- CVE-2023-29374
- CVE-2023-34540
- CVE-2023-34541
- CVE-2023-36095
- CVE-2023-36188
- CVE-2023-36258
- CVE-2023-38896
- CVE-2023-40267
- CVE-2023-40743
- CVE-2023-50447
- CVE-2024-42005
- CVE-2024-52046
- CVE-2025-32434
- CVE-2025-58367
- CVE-2025-64712
- CVE-2025-66516
- CVE-2026-22709
- CVE-2026-24118
- CVE-2026-24120
- CVE-2026-24781
- CVE-2026-25521
- CVE-2026-26332
- CVE-2026-26832
- CVE-2026-26956
- CVE-2026-27699
- CVE-2026-27962
- CVE-2026-31072
- CVE-2026-32304
- CVE-2026-33863
- CVE-2026-41409
- CVE-2026-41635
- CVE-2026-42778
- CVE-2026-42779
- CVE-2026-43997
- CVE-2026-44006
- CVE-2026-44008
- CVE-2026-44009
- CVE-2026-45411
- CVE-2026-45618
- CVE-2026-47065
- CVE-2026-47131
- CVE-2026-47208
- CVE-2026-53486
- CVE-2026-59873
- CVE-2026-9277
-
(SS) New rules:
-
(SS) New validity checks:
Release 30
-
(Reachability) Hex reachability analysis: The platform supports reachability analysis for vulnerabilities in Hex (Elixir) packages.
-
(ASPM) Multi-branch testing: You can add the same repository to more than one group. Each group tracks a different branch, with its own findings and testing scope. See the registration rules.
-
(ASPM) CLI OAuth login with refresh and logout: The Fluid Attacks CLI supports OAuth authorization-code login against the platform, with automatic token refresh and secure logout.
-
(DB) Malware status unified into vulnerable: The component page shows malware findings as vulnerable. Thus, this page uses the same term as the other pages of the platform.
-
(SAST) New rules:
-
(Reachability) New rules:
- CVE-2016-10541
- CVE-2017-1000228
- CVE-2017-1001002
- CVE-2017-16042
- CVE-2017-5941
- CVE-2018-1000620
- CVE-2018-13797
- CVE-2018-16486
- CVE-2018-16489
- CVE-2018-16491
- CVE-2018-16492
- CVE-2018-3750
- CVE-2019-10746
- CVE-2019-10747
- CVE-2019-15160
- CVE-2019-15657
- CVE-2019-19919
- CVE-2020-8149
- CVE-2022-39353
- CVE-2022-4742
- CVE-2023-42810
- CVE-2023-50966
- CVE-2024-21534
- CVE-2024-32962
- CVE-2024-34391
- CVE-2024-34392
- CVE-2024-34393
- CVE-2024-34394
- CVE-2024-57077
- CVE-2025-29774
- CVE-2025-29775
- CVE-2025-47949
- CVE-2025-57285
- CVE-2025-59936
- CVE-2025-6547
- CVE-2025-66565
- CVE-2025-66630
- CVE-2025-68428
- CVE-2026-1774
- CVE-2026-32686
- CVE-2026-32687
- CVE-2026-39821
- CVE-2026-47074
- CVE-2026-48591
- CVE-2026-48596
- CVE-2026-48598
- CVE-2026-56813
- CVE-2026-58225
-
(SS) New validity checks:
Release 29
-
(DB) Include/exclude filtering for CWE and weakness: The vulnerability filter panel has include and exclude modes for CWE and weakness. Thus, teams can show only the weakness types that they select, or remove categories from their view.
-
(ASPM) Export billing history authors as CSV: At the organization level, the authors table of the billing history has a CSV export option.
-
(SAST) New rules:
-
(Reachability) New rules:
- CVE-2013-7370
- CVE-2013-7371
- CVE-2014-3743
- CVE-2014-3744
- CVE-2014-8882
- CVE-2016-1000223
- CVE-2016-20018
- CVE-2017-1001004
- CVE-2020-14967
- CVE-2020-14968
- CVE-2020-7707
- CVE-2020-8132
- CVE-2021-23358
- CVE-2021-23369
- CVE-2021-23383
- CVE-2021-23436
- CVE-2021-23451
- CVE-2021-25949
- CVE-2021-26707
- CVE-2021-28918
- CVE-2021-30246
- CVE-2021-42740
- CVE-2021-45459
- CVE-2022-0686
- CVE-2022-1650
- CVE-2022-21190
- CVE-2022-21191
- CVE-2022-2216
- CVE-2022-22912
- CVE-2022-23806
- CVE-2022-2421
- CVE-2022-25860
- CVE-2022-26260
- CVE-2023-24538
- CVE-2023-24540
- CVE-2024-24790
- CVE-2024-3817
-
(SS) New validity checks:
Release 28
-
(ASPM) Secrets detection in the Peer Reviewer Assistant: On GitLab and Azure DevOps, the Peer Reviewer Assistant runs the Secrets Scanner on pull request diffs, together with SAST and SCA.
-
(MCP) Secrets Scanner tool in the MCP server: Authenticated AI agents can invoke the run_secrets_scanner tool. This tool guides the agents to detect hardcoded secrets and credentials in a codebase.
-
(DB) Events renamed to Signals: The vulnerability detail panel and the list filter show real-world exploitation activity as Signals. They show a simple count, with a tooltip that explains the metric.
-
(DB) Components section in the Database: The new Components section lists all the versions of a software component and shows which versions are vulnerable. It covers containers, binaries, and kernels, and not only dependency packages.
-
(DB) Package field links to its detail view: On vulnerability pages, the package field is a link. This link opens the page of the component in the new Components section and does not filter the vulnerability list.
-
(SAST) New rules:
- Elixir Cassandra Hardcoded Credentials
- Elixir Config Hardcoded Credentials
- Elixir Delete Path Traversal
- Elixir Finch Request Forgery
- Elixir Httpoison Request Forgery
- Elixir Mongo Hardcoded Credentials
- Elixir Redis Hardcoded Credentials
- Elixir Tesla Request Forgery
- Elixir Untrusted Data Deserialization
- Elixir Untrusted Open Redirect
- Java Api Sql Injection
- Yaml Hardcoded Weak Credentials
-
(SS) New rules:
-
(SS) New validity checks:
-
(Reachability) New rules:
Release 27
-
(IDE Plugin) Feature parity between VS Code and IntelliJ IDEA: All the features of the IDE extension are available in VS Code and in IntelliJ IDEA. In the two IDEs, you can see vulnerabilities, get remediation recommendations, and get autofixes.
-
(IDE Plugin) SCA remediation recommendations in IntelliJ IDEA: Developers can get AI-assisted remediation recommendations for SCA vulnerabilities directly from IntelliJ IDEA. VS Code had the same feature before.
-
(IDE Plugin) SCA autofixes for JavaScript and Python in both IDEs: The IDE extension produces diff-based autofixes for SCA vulnerabilities in JavaScript and Python package managers. This feature is available in VS Code and in IntelliJ IDEA.
-
(DB) VLAI Severity now available across the Database: Each vulnerability in the Database shows a VLAI severity rating (Critical, High, Medium, or Low). You can filter the vulnerabilities by this rating. Thus, teams can use an AI-assisted signal together with CVSS and EPSS when they prioritize fixes.
-
(SS) Validity checks: Secrets scanning checks a detected credential against its own provider and reports if the credential is active. Thus, teams can rotate live secrets first.
-
(SAST) New rules:
-
(SS) New rules:
- Firebase Fcm Api Key
- Paypal Secret Key
- Smtp Password
- Twitch Secret Key
- Zoom Secret Key
-
(SS) New validity checks:
-
(Reachability) New rules:
June
Release 26
-
(AI SAST) AI SAST expanded authorization and access control detection: The AI-assisted SAST scanner covers improper authorization for web services, RDS environments, and privilege escalation patterns (CWE-862).
-
(DAST-WEB) New rules:
-
(SAST) New rules:
-
(SS) New rules:
- Adafruit Api Key
- Cloudflare CA Key
- Cloudflare Global API Key
- Django Secret Key
- Ftp Password
- Jwt Token
- Laravel Secret Key
- Ldap Password
- MariaDB Credentials
- MySQL Credentials
- Oracle Jdbc Password
- Oracle Password
- Postman Api Token
- Prefect Api Key
- Pulumi Access Token
- Rabbitmq Password
- Rails Secret Key
- Redis Password
- Redshift Password
- Sendbird Access Token
- Sendinblue Api Key
- Sentry Api Token
- Shopify Api Token
- Shopify Shared Secret
- Snowflake Credentials
- Snyk Api Token
- Square Access Token
- Sumologic Access Key
- Supabase API Key
- Travisci Access Token
- Twilio Api Key
- Twilio Api Token
- Twitter Access Token
- Twitter Api Key
- Twitter Api Token
- Twitter Secret Key
- Typeform Api Token
- Vercel Api Token
- Weights And Biases Api Key
- Xai Api Key
- Yandex Access Token
- Yandex Api Key
- Zendesk Api Token
-
(Reachability) New rules:
Release 25
-
(DAST-WEB) New rules:
-
(SAST) New rules:
-
(SS) New rules:
-
(SCA) New support:
- Ruby runtime CVE detection from .gemspec: Runtime CVE detection supports Ruby projects that use .gemspec files.
- Python runtime CVE detection from Pipfile and Pipfile.lock: Runtime CVE detection supports Python projects that use Pipfile and Pipfile.lock.
-
(Reachability) New rules:
Release 24
-
(SCA) Runtime support for Go: The platform supports runtime reachability analysis for Go projects.
-
(SCA) Runtime support for Ruby: The platform supports runtime reachability analysis for Ruby projects.
-
(IDE Plugin) SCA custom fix in IntelliJ IDEA: Developers can view the custom fix for SCA vulnerabilities directly from IntelliJ IDEA.
-
(AI SAST) Expanded authorization coverage: The AI-assisted SAST scanner detects more authorization vulnerability patterns.
-
(DAST-WEB) New rules:
-
(SAST) New rules:
-
(SS) New rules:
-
(Reachability) New rules:
Release 23
-
(IDE Plugin) SCA autofix for Python: The IDE extensions of Fluid Attacks support these package managers: pip, Poetry, Pipenv, and uv. Thus, you can fix the SCA dependencies of Python projects with one click from these extensions.
-
(DAST-WEB) New rules:
-
(DAST-API) New rules:
-
(SAST) New rules:
- Dart Cryptography Pbkdf2 Weak Key Length
- Dart Ftp Unencrypted Connection
- Dart Information Exposure In Query String
- Dart Io Httpserver Insecure Bind
- Dart Pointycastle Argon2 Weak Memory
- Dart Shelf Server Insecure Bind
- Dart Smtp Unencrypted Connection
- Go Gin Insecure Samesite Cookie Attribute
- Go Insecure Samesite Cookie Attribute
- Go Mysql Empty Password In Dsn
-
(SS) New rules:
May
Release 22
-
(ASPM) Accuracy SLA now available on the platform: Customers with at least one group in the Advanced plan can see their Accuracy SLA directly on the platform.
-
(SCA) Elixir support: The SCA scanner supports Hex as a package manager. Thus, SCA scanning is available for Elixir projects.
-
(SCA) Rust support: The SCA scanner supports Cargo as a package manager. Thus, SCA scanning is available for Rust projects.
-
(DAST-WEB) New rules:
-
(DAST-API) New rules:
-
(SAST) New rules:
- Dart Cryptography Pbkdf2 Weak Iterations
- Dart Grpc Client Insecure Connection
- Dart Grpc Server Insecure Connection
- Dart Inappwebview Insecure Mixed Content
- Dart Pointycastle Pbkdf2 Weak Iterations
- Dart Pointycastle Pbkdf2 Weak Key Length
- Dart Postgres Insecure Connection
- Dart Postgres Ssl Verification Bypass
- Go Deprecated Encryption Function Use
- Go Deprecated Pemblock Encryption Functions
- Go Hardcoded Salt In Pbkdf2
- Go Insufficient Bcrypt Cost
- Go Insecure Scrypt Parameters
- Go Jwt Without Claims Validation
- Go Pbkdf2 Insufficient Iteration Count
- Go Redos Vulnerable Regex
-
(SS) New rules:
Release 21
-
(DB) Common name search for weaknesses: Users can search weaknesses in the Database by usual vulnerability names, such as IDOR, BOLA, or Broken Access Control. Users do not have to know the formal name.
-
(DAST-WEB) New rules:
-
(SAST) New rules:
- Dart Cryptography Hardcoded Salt
- Dart Cryptography Weak Rsa Key Size
- Dart Grpc Ssl Verification Bypass
- Dart Pointycastle Argon2 Hardcoded Salt
- Dart Pointycastle Weak Rsa Key Size
- Dart Webview Flutter Ssl Verification Bypass
- Go Deprecated Dsa Functions Use
- Go Gorm Plaintext Storage Of Password
- Go Hardcoded Aws Secret Access Key
- Go Insufficient Kdf Output Length
- Go Sql Plaintext Storage Of Password
- Go Unsafe Logger Injection
- Javascript Express Directory Listing
- Ruby Debugger Mode Use
- Ruby Error Information Disclosure
- Ruby Xss In Raw Helper
- Typescript Express Directory Listing
-
(SS) New rules:
Release 20
-
(IDE Plugin) Right-click link to criteria, platform and vulnerability description in IntelliJ IDEA: When you right-click a vulnerability in the IntelliJ IDEA plugin, the plugin shows direct links. These links go to its criteria page, platform entry, and vulnerability description on db.fluidattacks.com. Thus, developers have more context when they triage findings.
-
(ASPM) Scope banner with registered inputs count: A new informational banner in the Scope section shows a count summary of all registered inputs. Thus, teams can quickly see the coverage of their attack surface.
-
(DB) Filter rules by weakness: The rules filter in the Database can filter rules by weakness. Thus, users can quickly find the rules that apply to one security weakness.
-
(DB) Improved KEV exploit source count: The KEV signal shows the number of independent sources that report an existing exploit (0–n sources). This number replaces the previous binary display, and helps you prioritize vulnerabilities more clearly.
-
(DB) Reachability support filter: The Database has a new filter for reachability support. With this filter, users can show only the vulnerabilities for which reachability analysis is available.
-
(DB) Events filter: The Database has a new Events filter. With this filter, users can show only the vulnerabilities with related news articles or external internet references.
-
(DAST-WEB) New rules:
-
(SAST) New rules:
- Dart Cryptography Insecure Random Key Generation
- Dart Inappwebview Ssl Verification Bypass
- Dart Io Ssl Verification Bypass
- Dart Weak Hash Md5
- Dart Weak Hash Sha1
- Go Sensitive Information In Logs
- Go Trust Proxy On
- Go Unsafe Open Redirect
- Javascript Bunyan Sensitive Information In Logs
- Javascript Jwt Lack Of Expiration
- Javascript Log4Js Sensitive Information In Logs
- Javascript Pino Sensitive Information In Logs
- Javascript Sensitive Information Get Request
- Javascript Sensitive Information In Url
- Javascript Sensitive Information Indexeddb
- Javascript Winston Sensitive Information In Logs
- Ruby Logger Injection In Rails
- Ruby Sensitive Information In Logger
- Ruby Sensitive Persistent Cookie
- Ruby Session Jwt Lack Of Expiration
- Ruby Use Of Insecure Random Function
- Ruby Use Of Marshal Dangerous Function
- Scala Deprecated Defaulthttpclient Use
- Scala Integer Overflow In Spring
- Typescript Bunyan Sensitive Information In Logs
- Typescript Jwt Lack Of Expiration
- Typescript Log4Js Sensitive Information In Logs
- Typescript Pino Sensitive Information In Logs
- Typescript Sensitive Information Get Request
- Typescript Sensitive Information In Url
- Typescript Sensitive Information Indexeddb
- Typescript Winston Sensitive Information In Logs
-
(SS) New rules:
-
(Reachability) New rules:
- CVE-2011-4969
- CVE-2012-6708
- CVE-2015-6096
- CVE-2015-9251
- CVE-2016-10735
- CVE-2018-14040
- CVE-2018-14042
- CVE-2018-20676
- CVE-2018-20677
- CVE-2019-11358
- CVE-2019-12415
- CVE-2019-20149
- CVE-2019-8331
- CVE-2020-11022
- CVE-2020-11023
- CVE-2020-12265
- CVE-2020-15250
- CVE-2020-15366
- CVE-2020-23064
- CVE-2020-28469
- CVE-2020-28472
- CVE-2020-36518
- CVE-2020-7598
- CVE-2020-7608
- CVE-2020-7656
- CVE-2020-7729
- CVE-2020-7774
- CVE-2020-7788
- CVE-2020-9488
- CVE-2021-23343
- CVE-2021-23362
- CVE-2021-23364
- CVE-2021-23368
- CVE-2021-23424
- CVE-2021-29425
- CVE-2021-32640
- CVE-2021-32804
- CVE-2021-33623
- CVE-2021-37701
- CVE-2021-37713
- CVE-2021-3803
- CVE-2021-3807
- CVE-2021-43138
- CVE-2022-0122
- CVE-2022-0155
- CVE-2022-0235
- CVE-2022-0436
- CVE-2022-0536
- CVE-2022-1537
- CVE-2022-23539
- CVE-2022-24771
- CVE-2022-24772
- CVE-2022-24773
- CVE-2022-24999
- CVE-2022-25858
- CVE-2022-25883
- CVE-2022-33987
- CVE-2022-3517
- CVE-2022-36313
- CVE-2022-37599
- CVE-2022-37601
- CVE-2022-37603
- CVE-2022-38778
- CVE-2022-38900
- CVE-2022-45688
- CVE-2022-46175
- CVE-2023-0842
- CVE-2023-26115
- CVE-2023-26136
- CVE-2023-26159
- CVE-2023-36665
- CVE-2023-44270
- CVE-2023-45133
- CVE-2023-5072
- CVE-2024-11831
- CVE-2024-21536
- CVE-2024-28849
- CVE-2024-28863
- CVE-2024-29041
- CVE-2024-29180
- CVE-2024-29409
- CVE-2024-37890
- CVE-2024-4067
- CVE-2024-4068
- CVE-2024-43799
- CVE-2024-43800
- CVE-2024-45296
- CVE-2024-47081
- CVE-2024-47554
- CVE-2024-47764
- CVE-2024-52798
- CVE-2024-55565
- CVE-2025-12758
- CVE-2025-12816
- CVE-2025-13465
- CVE-2025-15284
- CVE-2025-22870
- CVE-2025-27152
- CVE-2025-27789
- CVE-2025-32996
- CVE-2025-32997
- CVE-2025-46653
- CVE-2025-47935
- CVE-2025-47944
- CVE-2025-48924
- CVE-2025-48997
- CVE-2025-50537
- CVE-2025-58754
- CVE-2025-5889
- CVE-2025-62718
- CVE-2025-64718
- CVE-2025-65945
- CVE-2025-66030
- CVE-2025-66031
- CVE-2025-66035
- CVE-2025-66471
- CVE-2025-68157
- CVE-2025-69873
- CVE-2025-7338
- CVE-2025-7339
- CVE-2025-7783
- CVE-2025-9288
- CVE-2026-21441
- CVE-2026-23745
- CVE-2026-2391
- CVE-2026-23950
- CVE-2026-24001
- CVE-2026-24842
- CVE-2026-25128
- CVE-2026-25547
- CVE-2026-25639
- CVE-2026-25896
- CVE-2026-26278
- CVE-2026-26960
- CVE-2026-26996
- CVE-2026-2739
- CVE-2026-27606
- CVE-2026-27903
- CVE-2026-27904
- CVE-2026-27942
- CVE-2026-29063
- CVE-2026-2950
- CVE-2026-29786
- CVE-2026-31802
- CVE-2026-31808
- CVE-2026-32141
- CVE-2026-32630
- CVE-2026-33036
- CVE-2026-33228
- CVE-2026-33349
- CVE-2026-33532
- CVE-2026-33671
- CVE-2026-33672
- CVE-2026-33750
- CVE-2026-33891
- CVE-2026-33894
- CVE-2026-33895
- CVE-2026-33896
- CVE-2026-33916
- CVE-2026-33937
- CVE-2026-33938
- CVE-2026-33939
- CVE-2026-33940
- CVE-2026-34043
- CVE-2026-3449
- CVE-2026-39865
- CVE-2026-40175
- CVE-2026-41242
- CVE-2026-4800
- CVE-2026-4867
- CVE-2026-4923
Release 19
- (DAST-WEB) New rules:
- (DAST-API) New rules:
- (SAST) New rules:
- Dart Cryptography Hardcoded Nonce
- Dart Insecure Storage Sql Injection
- Go Hardcoded Amqp Password
- Go Hardcoded Mongodb Password
- Go Hardcoded Redis Password
- Typescript Nest Mssql Injection
- Java Server Information Exposure
- Ruby Hardcoded Key For Token
- Scala Hardcoded Key In Secretkeyspec
- Scala Header Insecure Cors Configuration
- Scala Random Hardcoded Seed
- Scala Secure Random Hardcoded Seed Unsafe
- Scala Hardcoded Keyparameter Use
- Scala Hardcoded Password In Pbekeyspec
- (SS) New rules:
April
Release 18
- (Compliance) Enterprise-Grade Security & Compliance Certifications: Fluid Attacks achieved ISO/IEC 27001 and ISO/IEC 27701 certification, with controls aligned to ISO/IEC 27017 and ISO/IEC 27018. Fluid Attacks also has a SOC 2 attestation and SOC 3 report, PCI DSS validation, and measures designed to support GDPR compliance.
- (ASPM) The Health Check filter in the Git Repositories table now includes a third option: "Requested." Previously, this option was missing. For consistency, the filter options also have the same names as the values in the table column. "Yes" / "No" changed to "Included" / "Not included" / "Requested".
- (DB) Defines filters have been updated to recognize and expose the Rust ecosystem properly: Previously, support for Rust advisories was available only at the data/source level. At this time, the filter interface also fully shows this support.
- (IDE Plugin) SCA autofix for JavaScript: The IDE extensions of Fluid Attacks support these package managers: npm, Yarn, and Bun. Thus, you can fix the SCA dependencies of JavaScript projects with one click from these extensions.
- (SAST) New rules:
- Dart Hardcoded Http client Credentials
- Dart Jaguar Hardcoded Jwt Secret
- Dart Jsonwebtoken Hardcoded Jwt Secret
- Java Insecure File Permissions
- Java Redos User Input In Compile
- Java Unsafe Header X Frame Options
- Java Use Of Insecure Random
- Typescript Nest Typeorm Sql Injection
- Dart Hardcoded Crypto Iv
- Typescript Nest Mysql Injection
- Typescript Nest Pg Sql Injection
- Go Hardcoded PostgreSQL Password
- Java Data Leak Through Persistent Cookie
- Json Yaml Secrets Manager Privileges
- Typescript Nest Oracle Sql Injection
- Typescript Nest Sqlite Injection
Release 17
- (ASPM) Add filters.rootNickname in vulnerabilities: Added a filters.rootNickname parameter to group.vulnerabilities and finding.vulnerabilities. With this parameter, API users can filter vulnerabilities directly by root. They do not have to use ambiguous combinations of search, where, and whereStartsWith.
- (CI Gate) Add GitHub action: Added a custom GitHub Action for the CI Agent. With this action, clients can integrate the CI Agent directly into their CI pipelines, without manual setup or configuration.
- (SS) New rules:
- (DAST-WEB) New rules:
- (SAST) New rules:
- Java Vulnerable Spring Escape False
- Php Unsafe Target Blank Use
- Typescript Insecure Nest Injection
- Typescript Nest Sequelize Sql Injection
- Java Secure Random Hardcoded Seed Unsafe
- Javascript Express Fetch SSRF
- Javascript Express Http Https SSRF
- Typescript Express Fetch SSRF
- Typescript Express Http Https SSRF
- Typescript Unsafe Nest Axios SSRF
- Typescript Unsafe Nest Fetch SSRF
- Typescript Unsafe Nest Http Https SSRF
- Dart Webview Html Injection
- Dart Xss Public Storage Webview Injection
- Java Sensitive Information In Log4j Log
- Java Sensitive Information In Slf4j Log
- Java password field Missing Masking
- Dart Hardcoded Password In Connection
- Dart Smtp Hardcoded Password
- Java Hardcoded Key parameter Use
Release 16
- (ASPM) Improve "Add environment" flow: reorder fields and add Frontend/Backend distinction: Restructured the “Add environment” modal for a better configuration flow. The fields have a clearer sequence: environment type, connection method, production context, frontend/backend URL classification, and conditional authentication settings. The modal also gives contextual guidance.
- (CI GATE, CSPM, DAST, MAST, SCA, SAST) Deploy public container images to GHCR alongside DockerHub: Published public scanner images to GitHub Container Registry (GHCR) and migrated them to the centralized container-builder for unified CI workflows and multi-arch support.
- (DB) Enhancing EPSS Value with Temporal Context: Added a tooltip with a last-updated timestamp to the EPSS field. The tooltip clearly shows how current the data is. Thus, teams can prioritize vulnerabilities with more confidence and better information.
- (DB) Original filter for DB: Added an Original Severity filter to the vulnerabilities page. With this filter, users can filter by CVE source severity, together with the existing adjusted severity filter.
- (SS) Add secret scan github action: Added infrastructure and a GitHub Action for the new secret scanner. This work also makes the Docker image and publishes it to DockerHub and GHCR.
- (SS) New rules:
- (DAST-API) New rules:
- (DAST-WEB) New rules:
- (SAST) New rules:
- Go Hardcoded Cryptographic Key
- Javascript Marsdb Nosql Injection
- PHP Curl Unsafe X Frame Options
- PHP Mb Send Mail Parameter Tampering
- PHP Unsafe Header X Frame Options
- Typescript Marsdb Nosql Injection
- Javascript Insecure Deprecated Encryption
- PHP Parse Value Shadowing
- Typescript Insecure Deprecated Encryption
- Go Email Content Forgery
- Go Email Headers Forgery
- Go Weak Rsa Key Size
- Java Unsafe Logger Injection
- Javascript Cryptojs Passphrase Mode
- Javascript Injection Of Untrusted Content
- Javascript Reflected Xss Protection Header
- Typescript Cryptojs Passphrase Mode
- Typescript Injection Of Untrusted Content
- Typescript Reflected Xss Protection Header
Release 15
- (SCA) Add severity field and severity threshold to scanner output:
Added
cvss_v4_severityto scan results and astrictness_thresholdconfig flag. With this flag, pipelines fail only when the scanner finds vulnerabilities at or above the configured severity floor. - (IDE Plugin) Improve authentication and loading messages in IntelliJ plugin: Added visual state indicators (spinner, alert, and check icons). Also adjusted the dark mode contrast with standardized colors, for clearer feedback during authentication and while the plugin loads vulnerabilities.
- (ASPM) Redesign Groups data panel to show attack surface and vulnerabilities: Added new Attack Surface and Vulnerability Summary sections. These sections show repository coverage metrics (with/without OAuth). They also show details about the total vulnerabilities, the CVSSF, and the number of vulnerabilities for each severity.
- (ASPM) Migrate platform authentication to Auth0: Replaced in-house Google, Microsoft, and Bitbucket authentication flows with Auth0. Auth0 gives built-in MFA, OTP, and third-party integrations, and makes the application less complex.
- (ASPM) Track severity updates in vulnerability and weakness history: When you approve a severity update, the platform records a timestamped entry in the tracking timelines of the vulnerability and of the weakness.
- (SAST) New rules:
- Javascript Crypto Unsafe Empty Password
- Javascript Insecure Sensitive Information File Storage
- PHP Ssl Verification Disabled Setopt
- PHP Unsafe User Controlled Variable
- Python Fastapi Html Injection
- Python Starlette Html Injection
- Typescript Crypto Unsafe Empty Password
- Typescript Insecure Sensitive Information File Storage
- Javascript Bcrypt Unsafe Empty Password
- Javascript Jwt Unsafe Empty Password
- Javascript Sensitive Information In Jwt
- Javascript Sequelize Unsafe Empty Password
- PHP Insecure Samesite Cookie Attribute
- Typescript Bcrypt Unsafe Empty Password
- Typescript Jwt Unsafe Empty Password
- Typescript Sensitive Information In Jwt
- Typescript Sequelize Unsafe Empty Password
- Go Insecure Random Key Generation
- Python Django Path Traversal
- Python Django Reflected Xss
- Python Fastapi Path Traversal
- Python Starlette Path Traversal
- Javascript Manual CSRF Token Handling Ajax
- Javascript Manual CSRF Token Handling Axios
- Javascript Manual CSRF Token Handling Fetch
- Javascript Manual CSRF Token Handling Xhr
- Javascript Unsafe Csv Injection Csv Writer
- Javascript Unsafe Csv Injection Fast Csv
- Javascript Unsafe Csv Injection Fs
- PHP Regex With User Input
- Typescript Manual CSRF Token Handling Ajax
- Typescript Manual CSRF Token Handling Axios
- Typescript Manual CSRF Token Handling Fetch
- Typescript Manual CSRF Token Handling Xhr
- Typescript Unsafe Csv Injection Csv Writer
- Typescript Unsafe Csv Injection Fast Csv
- Typescript Unsafe Csv Injection Fs
- PHP Command Argument Injection
- PHP Insecure Channel Use Websocket Client
- PHP Mb Send Mail Header Injection
- PHP Session Trust Boundary Violation
- (SS) New rules:
- SONAR TOKEN
- AWS KEY
- DB CONNECTION STRING
- PRIVATE PEM KEY
- PRIVATE SSH KEY
Release 14
- (DB) Improve Fixes section: Reorganized the Fixes section with top-level groupings (Code, Infrastructure, Packages). Added a dedicated SCA navigation model (Ecosystem → Fix) with initial coverage for TypeScript, Python, and Kotlin.
- (DB) Add Exploit signal (ordinal) and improve EPSS display: Added exploit availability as an ordinal signal (0–n sources) with filterable groupings and simplified EPSS display format to support clearer vulnerability prioritization.
- (SAST) New rules:
- Html Import Map Missing Integrity
- Javascript Kony Browser Html String
- PHP Laravel Open Redirect
- Python SSRF Session Unvalidated Url
- Typescript Kony Browser Html String
- Go Smtp Hardcoded Password
- Go Use Of Hardcoded Password
- PHP Mail Header Injection
- PHP Unsafe Open Redirect
- PHP Unsafe Parameter Tampering
- Python Jwt Decode Without Verification
- Python Jwt None Algorithm
- Javascript Bunyan Log Forging
- Javascript Log4Js Log Forging
- Javascript Pino Log Forging
- Javascript Winston Log Forging
- PHP Sensitive Information Stored In Log
- PHP User Input In Danger Function
- Typescript Bunyan Log Forging
- Typescript Log4Js Log Forging
- Typescript Pino Log Forging
- Typescript Winston Log Forging
- (SS) New rules:
March
Release 13
- (IDE Plugin) Remove redundant repository selection pop-up when project is already open in IDE: When a project is open, the VSCode and Cursor extensions of Fluid Attacks automatically detect the active repository. Thus, the extensions do not show the repository selection pop-up.
- (ASPM) Standardize file input experience in Add File modal: The Upload button shows a loading state while the platform processes the file. When the process is complete, the modal closes and global notifications give feedback.
- (ASPM) Minimum privilege for organizations and groups: Introduced activity tracking for each organization and group. This tracking replaces the global last-activity check. Thus, the platform enforces least privilege: it revokes access only to inactive orgs/groups, and keeps access where the user is active.
- (ASPM) Restrict environment and repository exclusion to privileged roles only: Restricted scope exclusion permissions to group managers only. Thus, users and vulnerability managers cannot remove environments or repositories from the scope. This change reinforces least-privilege governance.
- (DB) Improve detail panel structure to show Base vs Adjusted CVSS + vectors: Scope shows Base (source) and Adjusted CVSS (Fluid) with vectors. It clearly shows the difference between them, for better traceability and clarity.
- (SAST) New rules:
- Dart Get Storage Insecure Data Storage
- PHP Hardcoded Cryptographic Key
- Scala Hardcoded Salt In Hash
- Scala Hash Without Salt
- PHP Hardcoded Salt In Hash
- PHP Weak Encryption Size
- Python Httpx Cleartext Sensitive Information
- Dart Insecure Storage Of Sensitive Data
- Go Path Traversal Open File
- PHP Hardcoded Cryptographic Iv
- Dart File Storage Of Sensitive Data
- PHP Insufficiently Protected Credentials
- Python Aiohttp Cleartext Sensitive Information
- Python Urllib3 Cleartext Sensitive Information
Release 12
- (ASPM) Add supported and tested columns to Lines table: Added two columns to the Lines table: language support and Machine testing status. These columns give visibility at the file level.
- (ASPM) Improve Groups filters: Updated the filters of the Groups section to make them work and to align them with the improvements to the target registration flow.
- (ASPM) Add Cursor to Integrations: Added Cursor as an available option in the platform Integrations section.
- (ASPM) Restrict environment exclusion toggle to authorized roles: Only authorized roles can use the exclusion toggle of environment URLs. This change prevents unauthorized scope changes and vulnerability closures.
- (CI Gate) Show EPSS and reachability in SCA execution logs: Added EPSS score and reachability status to execution logs for SCA vulnerabilities.
- (SAST) New rules:
- Scala Logging Of Sensitive Data
- Swift Sensitive Data In External Storage
- Swift Sensitive Data In Keyboard Logging
- C Sharp User Input Generate Improper Output
- C Sharp User Input In Content
- Python Unencrypted Ftp Connection
- Scala Redos With Untrusted Input
- Scala Spring Session Fixation
- PHP Unlink Path Traversal
- Python Insecure Snmp Connection
- Python Unencrypted Telnet Connection
- Scala Hardcoded Password In Connection
- Scala Unsafe Parameter Tampering
- PHP Sensitive Information In Jwt
- PHP Syslog Log Injection
- PHP Use Of Hardcoded Password
- PHP User Input Storage Sensitive Data
- Python Requests Cleartext Sensitive Information
Release 11
- (MCP) SCA remediation with AI agents: Added repository context configuration to the MCP server. Thus, AI agents can remediate SCA vulnerabilities autonomously.
- (ASPM) Display 'No fix available' guidance: Added actionable guidance when vulnerabilities have no remediation path (EOL packages, abandonware, pending fixes).
- (ASPM) Improve Location filter with selector and search options: Replaced the free-text Location filter with a selector. The selector supports nickname, base URL, prefix matching, and full-text search.
- (ASPM) Improve 'New Group' modal for target registration: Added two fields to the New Group flow: target type and target evaluation stage.
- (DB) Dynamic filter options: The Database makes the filter options dynamically from the available results. Thus, no combination of filters gives an empty result.
- (IDE Plugin) IDE SCA remediation options: Added multiple SCA remediation options to GenAI-powered fixes in the VSCode extension.
- (Docs) Add fix guide for transitive dependency vulnerabilities: Added a page that explains three strategies: lockfile refresh, overrides, and shrinkwrap removal.
- (Docs) Add SAST and SCA GitHub Actions to CLI docs: Documented the new SAST and SCA GitHub Actions with auto-detected scan modes.
- (SAST) New rules:
Release 10
(SAST) New rules:
- Python Django Open Redirect
- Python Fastapi Open Redirect
- Python Starlette Open Redirect
- Scala Use Unvalidated Forwards
- Swift User Input In Regular Expression
- Swift Information Exposure In Query String
- Python Fastapi Uncontrolled Format String
- Python Starlette Uncontrolled Format String
- Python Fastapi Sensitive Data Logging
- Python Starlette Sensitive Data Logging
- Scala Spring Unsafe Open Redirect
- Scala Spring Use Unvalidated Forwards
- Python Logging Config Insecure Listen
- Scala Secure Flag Not Set
- Swift Webview Xss Injection
- Javascript Unsafe Input Resource Injection
- Typescript Unsafe Input Resource Injection
February
Release 9
- (SCA) Add support for new package managers: Added support for CocoaPods (Podfile parser), Bun, and RubyGems (.gemspec) package managers.
- (SCA) Add SCA remediation options to vulnerability details: Added remediation options (closest min fix, safe fix, complete fix) for direct and transitive dependencies.
- (Docs & DB) Standardize central layout and sidebar widths: Constrained the widths of the primary content and the sidebar on large screens. This change makes the text easier to read and gives the layout more consistency.
- (ASPM) Update Groups table to match new group modal: Updated the Groups section structure to align with the new group creation flow and target registration improvements.
- (ASPM) Allow editing environment authentication field: You can edit the "Requires Authentication" field of existing environment records.
- (ASPM) Relocate CI Gate token and installation guide: Moved CI Gate token management and installation guide from Scope to DevSecOps section.
- (SAST) New rules:
- Dart Unsafe Input Path Traversal Relative
- Ruby Insufficiently Protected Credentials
- Javascript Weak Password Encoding Base64
- Python Boto3 Ssl Verification Bypass
- Python Ssl Certificate Verification Bypass
- Typescript Weak Password Encoding Base64
- Python Aiohttp Ssl Verification Bypass
- Python Websocket Ssl Verification Bypass
- Ruby Hardcoded Session Secret Token
- Scala Hardcoded Initialization Vector
- Swift Hardcoded Password In Urlcredentials
- Config Files Misconfiguration In Impersonation
- Config Files Disabled Session Id Regeneration
- Ruby Short Session Key
- Scala Play Plaintext Storage Sensitive Data
- Dart Tempfile Unencrypted Sensitive Information
- Dart Native Language Cmd Injection
- Scala Spring Plaintext Storage Sensitive Data
- Scala Unsafe Open Redirect
Release 8
(SAST) New rules:
- Python Http Uncontrolled Cors Origin
- Python Wsgiref Uncontrolled Cors Origin
- C Sharp Sensitive Information In Logs
- C Sharp Jwt Sensitive Information Exposure
- Python Django Sensitive Data Logging
- Ruby Ssl Certificate Verification Bypass
- Scala Jwt Sensitive Information Exposure
- C Sharp CSRF Protection Disabled
- Python Django Uncontrolled Cors Origin
- Ruby Unsafe Open Redirect
- Config Files Insecure Cookieless Configuration
- Python Urllib3 Ssl Verification Bypass
- Python Hardcoded Password In Connection
- Ruby Sensitive Cookie Without Httponly
- C Sharp Hardcoded Credentials In Directory
- C Sharp Parameter Tampering In Email
- Python Httpx Ssl Verification Bypass
Release 7
- (DAST) Update scanner technique to MAST: Updated the APK scanner to replace DAST with MAST in all of the flow. This change includes the Docker image (mast scan config.yaml).
- (DB) Make general search bar index vulnerabilities: Extended the indexing of the primary search bar to include vulnerabilities (for example, CVE identifiers). Thus, you can find and open vulnerabilities directly.
- (DB) Add "View JSON" link to vulnerability's detail page: Added a "View JSON" link to vulnerability pages. The link goes to the data.json endpoint and opens in a new tab.
- (DB) Improve Log in: Renamed "Get started" to "Try for free" and added a clear ghost "Log in" button in the top bar. Aligned the flow with the design system. This change includes an avatar dropdown with user info and a ghost "Log out."
- (DB) Scalable filter UX for Database: Grouped multiple vulnerability filters in the default Filter dropdown and removed the highlighted filters. Kept the highlighted filter only for a single dominant case, for scalability and a clean hierarchy.
- (DB) LLMs.txt: Added an llms.txt endpoint. Thus, LLMs can use DB pages more easily.
- (IDE Plugin) Enhance IntelliJ sidebar: Added severity icons to the IntelliJ plugin sidebar, categorized by typology, for better visual context and prioritization of weaknesses.
- (MCP) Add output file configuration to MCP scanner tool prompts: Added a default output section to the YAML examples in MCP scanner tools. This section makes the tools write the results to Fluid-Attacks-Results.csv, and not only to stdout.
- (SAST) New rules:
- C Sharp Session Cookie Injection
- C Sharp Api Use Hardcoded Password
- Ruby Sensitive Information Weak Sha1
- Ruby Sensitive Information Weak Md5
- Ruby Hardcoded Encryption Key
- Ruby Weak Cipher Encryption
- Ruby Weak Cipher Encryption Blowfish
- Ruby Hardcoded Password In Connection
- Ruby Unsafe Hardcoded Password
- Python Flask Sensitive Data Logging
- C Sharp Hardcoded Cryptographic Key
Release 6
- (Docs & DB) Add multiple authentication methods: Added Google, Microsoft, LinkedIn, Bitbucket, and internal login as authentication options.
- (DB) Add detection status to vulnerabilities: Added a flag that shows if each vulnerability had at least one detection.
- (ASPM) Add KEV and EPSS metrics to Package Details: Added KEV and EPSS metrics to the Package Details view to give clients better vulnerability context.
- (SAST) New rules:
January
Release 5
- (ASPM) Azure integration now supports Bug as a work item type: The Azure integration can make work items of type 'Bug'. This type is useful for users or clients when their projects do not have the 'Issue' type available.
- (SAST) New rules:
- Java Uncontrolled Memory Allocation
- JavaScript Kony Hardcoded Encryption Key
- JavaScript Hardcoded Password In Connection
- Typescript Kony Hardcoded Encryption Key
- Typescript Hardcoded Password In Connection
- Java Intent Sensitive Communication
- JavaScript React Native Missing Masking
- Typescript React Native Missing Masking
- Python Django Uncontrolled Format String
- Python Flask Uncontrolled Format String
- Python Tornado Uncontrolled Format String
- JavaScript Cordova Open Redirect
- JavaScript Kony Url Injection
- JavaScript SSL Verification Bypass
- Typescript Cordova Open Redirect
- Typescript Kony Url Injection
- Typescript Ssl Verification Bypass
- Java Unsafe Object Binding
- Java Insecure Storage Sensitive Information
- JavaScript Cordova File Manipulation
- Typescript Cordova File Manipulation
Release 4
- (ASPM) Prevent accidental rejection of access invitations: The invitation flow of the platform has one more confirmation step. This step prevents accidental rejections when automated tools scan the links in the email.
- (SAST) New rules:
- Go Insecure Temp File Creation
- Java Unrestricted File Upload Spring
- Java Ognl Expression Injection
- Java Observable Time Discrepancy
- Java Denial Of Service By Sleep
- JavaScript Httponly Flag Not Set
- JavaScript Insecure Samesite Cookie Attribute
- Typescript Httponly Flag Not Set
- Typescript Insecure Samesite Cookie Attribute
- Java One Way Hash Without Salt
- JavaScript Sensitive Information Weak Sha1
- JavaScript Sensitive Information Weak Md5
- Typescript Sensitive Information Weak Sha1
- Typescript Sensitive Information Weak Md5
- Java Cookie Without Validation
Release 3
- (ASPM) Warn users about potential additional costs when changing branches: When users change the branches of a repository in the scope section, the platform shows a warning and checkboxes. They make it clear that this action can change the cost of the service.
- (SAST) New rules:
- Go Unencrypted Ftp Connection
- Go Unencrypted Telnet Connection
- Java Use Of Hardcoded Password
- JavaScript Insecure Sce Configuration
- Java Spring Session Fixation
- Java Empty Password Connection
- JavaScript Client CSS Injection
- Typescript Client CSS Injection
- Go Zip Slip Path Traversal
- Java Unvalidated Forwards Use
- JavaScript Email Headers Forgery
- Typescript Email Headers Forgery
Release 2
- (ASPM) Mark AI-detected vulnerabilities (AI SAST): Added a visual AI indicator to AI SAST findings to highlight the new technique.
- (SAST) New rules:
- Javascript Dom Stored Xss
- Typescript Dom Stored Xss
- Javascript Client Dom Xss
- Typescript Client Dom Xss
- Javascript Unsafe Deserialization Untrusted Data
- Javascript Unsafe Module Inclusion
- Javascript Unsafe Require Module Inclusion
- Typescript Unsafe Deserialization Untrusted Data
- Typescript Unsafe Module Inclusion
- Typescript Unsafe Require Module Inclusion
- Go Insecure Http Server
- Go Cleartext Sensitive Information
Release 1
(SAST) New rules:
- F064 Java session id not regenerated
- F014 Dart mirrors unsafe reflection
Free trial: Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' pentesting team, complete this contact form.