vulns.co
/
GKData.io MCP

OWASP API Security Top 10

OWASP API Security Top 10:2023 is the current API list. There is no 2026 edition on the OWASP API Security project page.

Source: OWASP API Security Top 10:2023. The web application list is a different document: OWASP Top 10:2025.

CategoryNameHunt
API1:2023Broken Object Level AuthorizationIDOR and broken authorization
API2:2023Broken AuthenticationSession and cookie scope, OAuth and OIDC, JWT attacks
API3:2023Broken Object Property Level AuthorizationMass assignment
API4:2023Unrestricted Resource ConsumptionNone yet
API5:2023Broken Function Level AuthorizationNone yet
API6:2023Unrestricted Access to Sensitive Business FlowsBusiness logic
API7:2023Server Side Request ForgerySSRF hunting
API8:2023Security MisconfigurationSecurity misconfiguration
API9:2023Improper Inventory ManagementNone yet
API10:2023Unsafe Consumption of APIsNone yet

None yet means this catalog has no hunt whose question is that category. The web Top 10 does not fill the gap.