vulns.co
/
GKData.io MCP

BLVulnerability family

Business logic and concurrency.

State transitions, approval integrity, and transactional invariants. 14 disclosures · 34 related references · 4 diagrams.

Connected collection

Disclosures

Connected collection

Related learning

OWASP Cheat Sheet Series Implementation Guide

OWASP Forgot Password

Explains account-bound recovery challenges, limited lifetime and reuse, consistent responses, attempt controls, notifications and post-reset session handling.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

Authorization Cheat Sheet

Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Secure Code Review: baseline and change-focused review

Explains how whole-codebase reviews and change-focused reviews answer different assurance questions. Connects architecture, business requirements and existing findings to manual examination of data movement, control…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Transaction Authorization

Explains operation-specific approval: show significant transaction details, preserve authorized data, enforce valid state transitions and recheck authorization at execution.

Reviewed 2026-10-02Read

PostgreSQL Global Development Group Implementation Guide

PostgreSQL 18: Transaction Isolation and Business Invariants

Explains why a stable database snapshot alone does not preserve business rules across concurrent transactions. PostgreSQL distinguishes serializable consistency from explicit locking and requires serialization-failure…

Reviewed 2026-10-03Read

Internet Engineering Task Force / RFC Editor Technical Standard

RFC 9700: Best Current Practice for OAuth 2.0 Security

Consensus guidance updating OAuth's security model with deployment experience, stronger protocol requirements, and deprecated insecure patterns. A primary reference for identity integration reviews.

Reviewed 2026-10-02Read

Connected collection

Visual models

A failure retains the original caller, action and resource. An explicit access denial stops without protected data. A known recoverable operational failure can propose a fallback, but switching execution identity grants no extra caller entitlement. A separate application-policy decision evaluates that fallback for the original caller. Denied or indeterminate decisions stop without protected data. A permitted, scoped fallback returns only caller-permitted data.

Conceptual model Diagram

Fallbacks must preserve the original caller's authority

Original editorial defensive synthesis of the Instagram embedding disclosure and OWASP authorization guidance. The researcher attributes the disclosure to error handling that retrieved protected content under an…

Reviewed 2026-10-04Read

Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software