Skip to content

Tier5 OWASP / CWE exploit suite (gap-exploit-owasp-cwe-suite)

Date: 2026-05-24

Summary

Expands benchmarks/tier5_http/exploits/ with OWASP Top 10 (2021)–labeled rows for protocol, traversal, smuggling, injection, RNG, and leak classes. Adds builtin attack drivers, nginx_mitigations.toml exploit linkage, and check-tier5-exploit-owasp-cwe-suite.sh in httpd-plan-gates.

Verify

./scripts/check-tier5-exploit-owasp-cwe-suite.sh
HTTPD_GATES_SKIP_LIC_BUILD=1 ./scripts/httpd-plan-gates.sh