The DevSecOps Glossary
The definitive reference for software engineers. Understand modern vulnerability classes, compliance frameworks, and infrastructure security terms to build bulletproof applications.
Cross-Site Scripting (XSS)
A vulnerability where an attacker injects malicious client-side scripts into a trusted website, executing code in the victims' browsers.
Server-Side Request Forgery (SSRF)
A flaw that allows an attacker to force a server to make unauthorized requests to internal or external resources.
SQL Injection (SQLi)
An attack where malicious SQL statements are inserted into entry fields for execution, allowing manipulation of the backend database.
Insecure Direct Object Reference (IDOR)
An access control vulnerability where an application provides direct access to objects based on user-supplied input without authorization checks.
Cross-Site Request Forgery (CSRF)
Forces an end user to execute unwanted actions on a web application in which they are currently authenticated.
Remote Code Execution (RCE)
The most critical vulnerability class, allowing an attacker to execute arbitrary commands on the target server.
JWT Bypass & Weak Signing
Exploiting improperly configured JWTs, such as the 'none' algorithm or brute-forcing weak HMAC secrets.
Broken Access Control
When users can act outside of their intended permissions, commonly ranked as the #1 OWASP risk.
Security Misconfiguration
Failing to implement all security controls for a server, application, or cloud environment, or leaving defaults intact.
Shadow & Zombie APIs
Undocumented, unmonitored, or deprecated APIs that are still live and accessible to attackers.
Prompt Injection
An attack against LLM-powered applications where malicious user input manipulates the model's system prompt to execute unintended instructions.
Software Supply Chain Attack
An attack that compromises a software project by targeting its dependencies, build tools, or distribution infrastructure rather than the application code itself.
Row-Level Security (RLS)
A database feature (primarily in PostgreSQL and Supabase) that restricts which rows a user can access based on their identity, enforced at the database layer.
SSR Security Risks
Security vulnerabilities specific to Server-Side Rendering in frameworks like Next.js, where code executes on the server before being sent to the client.
Zero-Day Vulnerability
A previously unknown software vulnerability that is actively exploited by attackers before the vendor has released a patch.
Secrets Management
The practice of securely storing, distributing, and rotating sensitive credentials such as API keys, database passwords, and encryption keys.
Privilege Escalation
An attack where a user gains higher access rights than they are authorized for, either vertically (user → admin) or horizontally (user A → user B's data).
Container Escape
An attack where a process running inside a Docker container breaks out of its isolation boundary and gains access to the host operating system.
Insecure Deserialization
A vulnerability where an application deserializes untrusted data without validation, allowing attackers to manipulate serialized objects to execute arbitrary code.
Rate Limiting & DoS Protection
Security controls that restrict the number of requests a client can make to an API within a given time window, preventing abuse and denial of service attacks.