OWASP API Security Top 10
OWASP API Security Top 10:2023 is the current API list. There is no 2026 edition on the OWASP API Security project page.
Source: OWASP API Security Top 10:2023. The web application list is a different document: OWASP Top 10:2025.
| Category | Name | Hunt |
|---|---|---|
| API1:2023 | Broken Object Level Authorization | IDOR and broken authorization |
| API2:2023 | Broken Authentication | Session and cookie scope, OAuth and OIDC, JWT attacks |
| API3:2023 | Broken Object Property Level Authorization | Mass assignment |
| API4:2023 | Unrestricted Resource Consumption | None yet |
| API5:2023 | Broken Function Level Authorization | None yet |
| API6:2023 | Unrestricted Access to Sensitive Business Flows | Business logic |
| API7:2023 | Server Side Request Forgery | SSRF hunting |
| API8:2023 | Security Misconfiguration | Security misconfiguration |
| API9:2023 | Improper Inventory Management | None yet |
| API10:2023 | Unsafe Consumption of APIs | None yet |
None yet means this catalog has no hunt whose question is that category. The web Top 10 does not fill the gap.