OWASP Top 10 - 2025 Prevention¶
This page maps the OWASP Top 10 - 2025 categories to the Secure Coding Guide. Each section there has a shared block of principles plus stack-specific implementation in tabs — click Java stack or Go stack once and the choice sticks across the site.
| # | Category | Section |
|---|---|---|
| A01 | Broken Access Control | Broken Access Control |
| A02 | Security Misconfiguration | Security Misconfiguration |
| A03 | Software Supply Chain Failures | Software Supply Chain Failures |
| A04 | Cryptographic Failures | Cryptographic Failures |
| A05 | Injection | Injection |
| A06 | Insecure Design | Insecure Design |
| A07 | Authentication Failures | Authentication Failures |
| A08 | Software and Data Integrity Failures | Software and Data Integrity Failures |
| A09 | Logging and Alerting Failures | Logging and Alerting Failures |
| A10 | Mishandling of Exceptional Conditions | Mishandling of Exceptional Conditions |