The DevSecOps Glossary

The definitive reference for software engineers. Understand modern vulnerability classes, compliance frameworks, and infrastructure security terms to build bulletproof applications.

Cross-Site Scripting (XSS)

A vulnerability where an attacker injects malicious client-side scripts into a trusted website, executing code in the victims' browsers.

Learn more

Server-Side Request Forgery (SSRF)

A flaw that allows an attacker to force a server to make unauthorized requests to internal or external resources.

Learn more

SQL Injection (SQLi)

An attack where malicious SQL statements are inserted into entry fields for execution, allowing manipulation of the backend database.

Learn more

Insecure Direct Object Reference (IDOR)

An access control vulnerability where an application provides direct access to objects based on user-supplied input without authorization checks.

Learn more

Cross-Site Request Forgery (CSRF)

Forces an end user to execute unwanted actions on a web application in which they are currently authenticated.

Learn more

Remote Code Execution (RCE)

The most critical vulnerability class, allowing an attacker to execute arbitrary commands on the target server.

Learn more

JWT Bypass & Weak Signing

Exploiting improperly configured JWTs, such as the 'none' algorithm or brute-forcing weak HMAC secrets.

Learn more

Broken Access Control

When users can act outside of their intended permissions, commonly ranked as the #1 OWASP risk.

Learn more

Security Misconfiguration

Failing to implement all security controls for a server, application, or cloud environment, or leaving defaults intact.

Learn more

Shadow & Zombie APIs

Undocumented, unmonitored, or deprecated APIs that are still live and accessible to attackers.

Learn more

Prompt Injection

An attack against LLM-powered applications where malicious user input manipulates the model's system prompt to execute unintended instructions.

Learn more

Software Supply Chain Attack

An attack that compromises a software project by targeting its dependencies, build tools, or distribution infrastructure rather than the application code itself.

Learn more

Row-Level Security (RLS)

A database feature (primarily in PostgreSQL and Supabase) that restricts which rows a user can access based on their identity, enforced at the database layer.

Learn more

SSR Security Risks

Security vulnerabilities specific to Server-Side Rendering in frameworks like Next.js, where code executes on the server before being sent to the client.

Learn more

Zero-Day Vulnerability

A previously unknown software vulnerability that is actively exploited by attackers before the vendor has released a patch.

Learn more

Secrets Management

The practice of securely storing, distributing, and rotating sensitive credentials such as API keys, database passwords, and encryption keys.

Learn more

Privilege Escalation

An attack where a user gains higher access rights than they are authorized for, either vertically (user → admin) or horizontally (user A → user B's data).

Learn more

Container Escape

An attack where a process running inside a Docker container breaks out of its isolation boundary and gains access to the host operating system.

Learn more

Insecure Deserialization

A vulnerability where an application deserializes untrusted data without validation, allowing attackers to manipulate serialized objects to execute arbitrary code.

Learn more

Rate Limiting & DoS Protection

Security controls that restrict the number of requests a client can make to an API within a given time window, preventing abuse and denial of service attacks.

Learn more