## Summary `ciphertextContainer.UnmarshalJSON` decodes the third `:`-separated component of a `vault:vX:base64...` ciphertext and then unconditionally takes a 12-byte prefix slice for the AES-GCM nonce: `c.nonce = fullCiphertext[:aesGCMNonceSize]`. If the decoded blob is shorter than 12 bytes, the slice expression panics. The panic happens before any cryptographic operation, while the JSON body of the request is still being parsed inside the request handler. Because the handler is invoked from `net/http`'s standard handler goroutine, the panic is recovered to a 500 response, but the request handler aborts mid-execution and the recovered panic appears in the Coordinator's logs. An authenticated workload that holds a valid mesh certificate for any `WorkloadSecretID` can trigger the panic at will, producing log spam, request-failure metrics, and a slow but cheap denial of service against the transit-engine endpoint. ## Details ### the panicking slice `coordinator/internal/transitengineapi/crypto.go:64-88`: ```go // UnmarshalJSON umarshalls a json string to a ciphertextContainer holding the version prefix, // decoded base64 nonce and ciphertext. func (c *ciphertextContainer) UnmarshalJSON(data []byte) error { var encoded string if err := json.Unmarshal(data, &encoded); err != nil { return err } // Split "vault:vX:base64" format parts := strings.SplitN(encoded, ":", 3) if len(parts) < 3 { return fmt.Errorf("invalid ciphertext format") } version, err := extractVersion(parts[1]) if err != nil { return fmt.Errorf("ciphertext version: %w", err) } c.keyVersion = version fullCiphertext, err := base64.StdEncoding.DecodeString(parts[2]) if err != nil { return fmt.Errorf("decoding ciphertext: %w", err) } c.nonce = fullCiphertext[:aesGCMNonceSize] // PANIC when len(fullCiphertext) < 12 c.ciphertext = fullCiphertext[aesGCMNonceSize:] return nil } ``` `aesGCMNonceSize = 12` (defined at line 33). There is no length check on `fullCiphertext`. If `parts[2]` decodes to fewer than 12 bytes (which happens for any base64 string shorter than ~16 characters), the slice expression `fullCiphertext[:aesGCMNonceSize]` triggers Go's runtime panic `runtime error: slice bounds out of range [:12] with length N`. `UnmarshalJSON` is reached from `parseRequest`: ```go // coordinator/internal/transitengineapi/transitengineapi.go:292-302 func parseRequest(r *http.Request, into any) error { defer r.Body.Close() if err := validateContentType(r); err != nil { return err } if err := json.NewDecoder(r.Body).Decode(into); err != nil { return err } return nil } ``` which is called inside `getDecryptHandler` (line 178-237) before any other processing. ### auth requirement is real but trivial to satisfy for any registered workload The transit-engine HTTP server (`transitengineapi.go:74-100`) configures `tls.RequireAndVerifyClientCert` with the Coordinator's mesh CA pool. The handler is wrapped by `authorizationMiddleware` (line 348-357) which calls `authorizeWorkloadSecret` (line 241-254). That function reads the `WorkloadSecretOID` extension from the peer cert and requires it to match the URL path's `{name}` segment. Any workload that has gone through the normal initializer / meshapi flow (`coordinator/internal/meshapi/meshapi.go:71-119`) and has a non-empty `WorkloadSecretID` in its `PolicyEntry` is issued a mesh cert with the matching extension, so the path-name authorisation is automatically satisfied for whichever `workloadSecretID` the manifest assigned to that workload. There is no rate limiting, no proof-of-work, and no audit log on triggering the panic. ### what happens after the panic `net/http` wraps each handler in a recovered goroutine, so the panic does not crash the Coordinator process. Instead: 1. The Go runtime captures the panic, logs `http: panic serving <peer>: runtime error: slice bounds out of range` to stderr together with a goroutine stack trace. 2. The connection is hung up without a response body (`http.Server.serve` calls `c.close()` in the recovery path). 3. The grpc-prometheus / handler metrics (registered via `promRegistry`) record the request as failed. 4. The recovered panic appears in the Coordinator's logs / journald, creating noise that an operator monitoring a real attack would have to filter out. A workload that wants to amplify the impact can: * Loop the request to fill the journal with stack traces (cheap operation per request, expensive log volume). * Combine with a second valid workload identity to bypass any per-cert rate limiting added later. * Use the panic stack trace (which contains internal source paths) as a fingerprint to determine the exact Coordinator version in lieu of a `/version` endpoint. The panic also avoids returning a JSON error body to the caller, so callers that depend on a structured error are forced into a less informative failure mode (HTTP-level connection close). ## PoC The bug is deterministic. Drop the following test into `coordinator/internal/transitengineapi/crypto_test.go`: ```go func TestCiphertextContainer_UnmarshalJSON_ShortBlobPanics(t *testing.T) { // "AAAA" base64-decodes to 3 bytes, well under aesGCMNonceSize=12. body := []byte(`"vault:v1:AAAA"`) defer func() { if r := recover(); r == nil { t.Fatalf("expected panic, got nil") } }() var c ciphertextContainer _ = c.UnmarshalJSON(body) // panics: slice bounds out of range [:12] with length 3 } ``` End-to-end against a running Coordinator (omitted for static review; would require a Contrast cluster and a mesh-certificate-holding workload): ```bash $ curl -k --cert workload.crt --key workload.key \ -H 'Content-Type: application/json' \ -d '{"ciphertext":"vault:v1:AAAA","associated_data":""}' \ https://coordinator:8200/v1/transit/decrypt/<my-workload-secret-id> # Connection: closed without HTTP response body. # Coordinator log: # http: panic serving 10.0.0.5:54321: runtime error: slice bounds out of range [:12] with length 3 # goroutine 4711 [running]: # net/http.(*conn).serve.func1(...) # net/http/server.go:1883 +0xb0 # panic({0x...?, 0x...?}) # runtime/panic.go:770 +0x132 # github.com/edgelesssys/contrast/coordinator/internal/transitengineapi.(*ciphertextContainer).UnmarshalJSON(...) # coordinator/internal/transitengineapi/crypto.go:85 +0x... ``` ## Impact * **Soft denial of service** against the transit-engine endpoint per workload identity. The Coordinator process survives because of `net/http`'s panic recovery, but each panicked request consumes CPU for the recovery / stack dump and floods the operator's logs. * **Information disclosure via stack trace** in the Coordinator log. The trace pins the Coordinator binary version, the build path of the `transitengineapi` package, and exact line numbers of internal source. This is a low-grade fingerprint, but it is leaked even to operators who would normally only see the binary version through controlled means. * **Loss of structured error reporting**: legitimate decrypt requests sharing the panicked log lines may be harder to attribute, and the API consumer sees a connection-close instead of a 4xx response, masking the cause. CVSS rationale: `AV:N`, `AC:L`, `PR:L` (any workload with a transit-engine permission can do this), `UI:N`, `S:U`, `C:N` / `I:N` / `A:L` (low availability impact: log noise + per-request CPU cost; no full DoS because Go's HTTP panic recovery keeps the process up). Score `3.1`. ## Recommended Fix Validate the decoded length before slicing. The minimal change at `coordinator/internal/transitengineapi/crypto.go:81-87`: ```go fullCiphertext, err := base64.StdEncoding.DecodeString(parts[2]) if err != nil { return fmt.Errorf("decoding ciphertext: %w", err) } if len(fullCiphertext) < aesGCMNonceSize { return fmt.Errorf("ciphertext is too short: got %d bytes, expected at least %d for the nonce", len(fullCiphertext), aesGCMNonceSize) } c.nonce = fullCiphertext[:aesGCMNonceSize] c.ciphertext = fullCiphertext[aesGCMNonceSize:] return nil ``` A defence-in-depth tightening would also reject ciphertexts with `len(fullCiphertext) <= aesGCMNonceSize` (which would yield an empty actual ciphertext that AES-GCM open would later reject anyway, but a sharper boundary fails earlier with a clearer error). Add a unit test along the lines of the PoC that asserts a clean error rather than a panic.
PoC: xiaomi15-dada-cve-2026-64560
Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8
PoC: cve-2026-32475-elementor-pro-lab
A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)
PoC: CVE-2026-58138
CVE-2026-58138
PoC: CVE-2026-41940
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
PoC: CVE-2024-12356
Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)
PoC: CVE-2026-85046
CVE-2026-85046
PoC: CVE-2026-62735
Windows HTTP.sys integer overflow -> nonpaged pool overflow LPE PoC (CVE-2026-62735): crash + full SYSTEM exploit; for authorized testing
PoC: CVE-2026-82329-JFrog-Artifactory-Auth-Bypass
CVE-2026-82329 — JFrog Artifactory (self-hosted) Auth Bypass
PoC: CVE-2026-65349
CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)
PoC: CVE-2026-65343
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
PoC: CVE-2026-65330
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
PoC: CVE-2026-64788
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
PoC: CVE-2026-52774-YESWIKI-XSS
a reflected XSS vulnerability in YesWiki's Bazar widget handler.
PoC: netty-http2-check
CVE-2025-55163 / CVE-2026-56819: offline checker for the 7 netty-codec-http2 CVEs. Tells you which ones you are exposed to, and the one version that fixes all seven (4.1.136.Final / 4.2.16.Final) - written on none of the advisories. Does not scan pom.xml on purpose: WebFlux pulls it in transitively.
PoC: CVE-2026-0920
A PoC exploit for CVE-2026-0920 - LA-Studio Element Kit / Unauthenticated Privilege Escalation
PoC: CVE-2026-84645
Jenkins PersistenceRoot Deserialization RCE (SECURITY-3972) — PoC & analysis. Requires Item/Configure; affects weekly <= 2.579 / LTS <= 2.568.2
PoC: cyberthreat_DBSproject
threat = { "id": "CVE-2026-0001", "title": "Apache HTTP Server Remote Code Execution", "vendor": "Apache", "product": "HTTP Server", "description": "A vulnerability in Apache HTTP Server allows remote attackers to execute arbitrary code.", "cvss": 9.8, "kev": True, "published": "2026-06-30" }
PoC: CVE-2026-6471
CVE-2026-6471
PoC: CVE-2026-75865
Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC
PoC: CVE-2026-32475
CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE
PoC: CVE-2023-42793-TeamCity-Unauthenticated-RCE
A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).
PoC: cve-2026-6471-postgres-logical-decoding-dlopen
postgres CVE-2026-6471 Exploit
PoC: gpgsm-cve-2026-57062-cms-gcm-short-tag
gpgsm CVE-2026-57062 exploit POC
PoC: CVE-2025-4255---Buffer-Overflow
Exploit Framework for CVE-2025-4255
PoC: gha-lab-4a8fad8536
Security-research lab reproducing CVE-2026-39382 (GHSA-5jxf-vmqr-5g82): command injection in dbt-labs reusable workflow open-issue-in-repo.yml, driven by a dbt-core-style docs-issue.yml caller
PoC: gha-lab-ed7a1740c4
Security-research lab: controlled reproduction of GHSA-3g6g-gq4r-xjm9 / CVE-2026-35580 (GitHub Actions workflow_dispatch input shell injection) against a pinned snapshot of NationalSecurityAgency/emissary
PoC: gha-lab-85f022290a
Research lab reproduction of CVE-2026-34243 (GHSA-r4fj-r33x-8v88): command injection via issue_comment.body in .github/workflows/comment.yaml — snapshot of njzjz/wenxian@ca4e04de86aa970c0e3cb1c7f2bd103d339fbe51
PoC: gha-lab-9b5e3ccfbe
Security-research lab: reproduction of CVE-2026-33475 (GitHub Actions script injection via PR branch name in deploy-docs-draft.yml), snapshot of langflow-ai/langflow
PoC: research-cve-2026-85649
[MIRROR] The CVE-2026-85649 Security Research Publication.
PoC: gha-lab-61c59f4acb
Security-research lab: controlled reproduction of CVE-2026-33075 (pwn request in labring/FastGPT preview-image workflow, pull_request_target + checkout-of-fork + privileged buildx push)
PoC: gha-lab-3f1ff30e9c
Authorized security-research lab reproducing CVE-2026-31852 (jellyfin/jellyfin-ios pull_request_target pwn in code-quality.yml) — isolated snapshot, not the upstream project
PoC: gha-lab-ca4fa82ac5
Security-research lab: reproduction of CVE-2026-29075 (GHSA-3j55-5q6x-2h48) in mesa/mesa benchmarks.yml pull_request_target workflow — single-commit snapshot for authorized vulnerability reproduction.
PoC: gha-lab-6c3094af9e
Authorized security-research lab reproducing CVE-2026-27941 (pwn request in pull_request_target workflows) — snapshot of openlit/openlit
PoC: gha-lab-a7f6217d26
Security-research reproduction of CVE-2026-27938 / GHSA-4q9f-mjxf-rx7x (GitHub Actions expression injection in release workflows) — snapshot of wp-graphql/wp-graphql at b216fe22f3a119f256511ec7353f536fee6886ac
PoC: cve-2026-19900-PoC
cve-2026-19900-PoC
PoC: CVE-2026-85769
Heap out-of-bounds read in libtpms TPM 2.0 state deserialization — CVE-2026-85769
PoC: CVE-2026-19632
Unauthenticated account takeover PoC for TranslatePress Multilingual <= 3.3.1 (WordPress)
PoC: CVE-2026-11613
Divi Ajax Filter <= 5.1.2 Unauthenticated Local File Inclusion via 'custom_loop_template'
PoC: gha-lab-25b7988758
Authorized security-research reproduction of CVE-2026-27701 / GHSA-xh9w-5859-x97j (live-codes/livecodes @ 8017e01): untrusted PR title interpolated into i18n-update-pull github-script block.
PoC: copy-fail-CVE-2026-31431-cpp
https://github.com/theori-io/copy-fail-CVE-2026-31431 but ported to c++ for fun
PoC: CVE-2026-83548-checker
Non-intrusive detector for SonicWall SMA 1000 exposure to CVE-2026-83548/-83549 (version/patch-state check; no exploitation)
PoC: gha-lab-b16a4f3554
Security-research lab: CVE-2026-24480 pull_request_target pre-commit RCE in qgis/QGIS (snapshot at vulnerable commit)
PoC: Yordam-Kutuphane-Otomasyonunda-Coklu-HTML-Enjeksiyonu
CVE-2026-77818 - Yordam Kütüphane Otomasyon Sistemi - Üç ayrı noktada yansıtılmış HTML enjeksiyonu, form action ele geçirme ve kimlik bilgisi hırsızlığı (CWE-79)
PoC: jsherp-user-info-idor
VulDB advisory: jshERP authenticated /user/info IDOR and password-digest replay after CVE-2025-60800
PoC: gha-lab-7927d7d06f
Security-research lab reproducing CVE-2026-22869 (pwn) — arbitrary code execution in privileged pull_request_target run via npx local-bin hijack, snapshot of eigent-ai/eigent @ 2a406536
PoC: cve-2026-31431
PoC for CVE-2026-31431
PoC: gha-lab-b5c1313658
Authorized security-research lab reproducing CVE-2026-1699 (pwn request in preview.yml) — snapshot of eclipse-theia/theia-website
PoC: CVE-2026-63077
CVE-2026-63077 - Unauthenticated RCE exploit for JetBrains TeamCity via Agent Polling Deserialization. Supports mass scanning, multi-threading, and interactive shell. For authorized security testing only.
PoC: CVE-2026-6471
CVE-2026-6471 - Draft or TODO
PoC: CVE-2026-73554
CVE-2026-73554 - Draft or TODO
PoC: CVE-2026-19516
CVE-2026-19516
PoC: gha-lab-51c6b6d0a0
Lab reproducing CVE-2025-67727 (parse-community/parse-server ci-performance.yml pull_request_target RCE at e78e58d) — authorized security research
PoC: gha-lab-6904b2ccbe
Security-research lab: reproduction of CVE-2025-61584 (GHSA-9g7x-737f-5xpc) — command injection via github.head_ref in pull_request_target workflow (.github/workflows/pr.yml)
PoC: CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine
Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine
PoC: cve-disclosures
CVE-2024-57551, CVE-2024-57552, CVE-2024-57553 advisories by Aman Bahiniya
PoC: unit-01-severity-vs-risk-reflection
cve-2026-25524 Holds no customer payment data, no monitoring in place, monitored 24/7 The CVSS score is technically serious, but it doesn't tell how exposed it is, weather our existing defenses would stop or contain an attack. We should confirm the vulnerable component is reachable by untrust input in our environment.
PoC: gha-lab-d14c91f1bb
Security-research lab: reproduction of CVE-2025-58371 (GitHub Actions command injection via PR title in Discord PR Notifier), snapshot of RooCodeInc/Roo-Code @ 08a825f9bb0086a88cff5a79b9af4731bba7d076
PoC: thymeleaf-check
Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your version line has a fix at all (3.0.x: it does not)
PoC: CVE-2024-36058
CVE-2024-36058 — Authenticated Time-Based Blind SQL Injection in Koha Library Software < 22.05.22 (opac-sendbasket.pl). Advisory + PoC by Hacklantic.
PoC: CVE-2024-36057
CVE-2024-36057 — Authenticated OS Command Injection in Koha Library Software < 22.05.22 (upload-cover-image.pl). Advisory + PoC by Hacklantic.
PoC: gha-lab-aa1cbc9bcf
Authorized security-research reproduction of CVE-2025-54594 (GHSA-588g-38p4-gr6x): privileged issue_comment-triggered canary release workflow checking out untrusted fork code and running its npm scripts with GITHUB_TOKEN/NPM_TOKEN in env. Snapshot of callstackincubator/react-native-bottom-tabs @ d765b1f695762490327dcb8f6a2f17542cf0abdb.
PoC: CVE-2026-82329-poc
CVE-2026-82329 Poc
PoC: CVE-2025-34158-CVE-2020-5741
CVE-2025-34158, CVE-2020-5741 - Draft or TODO
PoC: gha-lab-ba981941f0
Security-research lab reproducing CVE-2025-54430 (GHSA-wrg3-xqw8-m85p): secrets exfiltration via issue_comment-triggered Benchmark Bot in dedupeio/dedupe. Snapshot of dedupeio/dedupe@54ecfe77d41390da66899596834a2bde3712c966.
PoC: gha-lab-f894926966
Authorized security-research reproduction lab for CVE-2025-54415 (GHSA-g5hx-xv45-9whg): astronomer/dag-factory snapshot at 464c75a — pull_request_target head-SHA checkout executes attacker-controlled hatch scripts in base-repo context
PoC: gha-lab-6926364d94
Security research lab reproducing CVE-2025-53546 (GHSA-h87r-5w74-qfm4): pull_request_target arbitrary code execution in RSSNext/Folo's auto-fix lint workflow — authorized, isolated reproduction
PoC: CVE-2025-8518
CVE-2025-8518 - Draft or TODO
PoC: gha-lab-3b0a828a69
Security-research lab reproducing CVE-2025-53104 (GHSA-432r-9455-7f9x): command injection in discussion-to-slack.yml of gluestack/gluestack-ui
PoC: gha-lab-e8902eccd3
Security research lab: reproduction of CVE-2025-52467 (pgai pull_request_target workflow code execution / GITHUB_TOKEN exfiltration) — snapshot of timescale/pgai
PoC: tomcatfileread
CVE-2020-1938 (Ghostcat) Tomcat AJP file read/file include PoC with python3 port
PoC: CVE-Chamilo-LMS
CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602, CVE-2026-70647, CVE-2026-70648 - Draft or TODO
PoC: gha-lab-2f775f277c
Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d
PoC: CVE-2026-31787
Linux kernel double free in Xen privcmd driver
PoC: gha-lab-fb6df3d456
Authorized security-research lab reproducing CVE-2025-46820 (GHSA-cwj7-6v67-2cm4): GITHUB_TOKEN persisted into publicly downloadable CI artifacts in phpgt/Dom. Snapshot of phpgt/Dom @ b73d7e8.
PoC: CVE-2026-20212
CVE-2026-20212 - Draft or TODO
PoC: CVE-2026-56718
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
PoC: psa-2026-00043-recovery
Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)
PoC: gha-lab-ba8e0c4217
Authorized security-research lab: reproduction of CVE-2024-42370 / GHSA-4hq2-rpgc-r8r7 (env injection in docs-preview.yml) — snapshot of litestar-org/litestar@18d84d84
PoC: CVE-2026-65643-PoC-Toolkit
🧰 CVE-2026-65643 – cPanel Domain Parking RCE Toolkit (CVSS 8.7) | Red/Blue Team suite for unpatched cPanel & WHM 11.x (110,134,136,138). 2 tools: Full Exploit (reverse shell, webshell, persistence, root passwd, file R/W, mass scan, Tor), Blue Team PoC (detection, reporting, audit). w/Python. 🦾 Only Use Ethically, Stay Legal <3
PoC: CVE-2026-4813
PoC for CVE-2026-4813
PoC: cve-2026-75604
Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.
PoC: CVE-2026-82329
CVE‑2026‑82329 is a critical authentication bypass in JFrog Artifactory (CVSS 9.8) allowing unauthenticated attackers to obtain full administrative privileges. Actively exploited in the wild. Affects self‑hosted versions before patches. PoC for authorized testing only.
PoC: CVE-2026-52810
CVE-2026-52810 - Draft or TODO
PoC: iOS26.6-CVE-2026-64788
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
PoC: CVE-2026-80428
CVE-2026-80428 PoC
PoC: iOS26.6-CVE-2026-65343
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
PoC: CVE-2026-80428
CVE-2026-80428 PoC
PoC: gha-lab-b1fe4918c0
Authorized security-research lab: reproduction of CVE-2025-32958 (GHSA-8c7v-vccv-cx4q) — GITHUB_TOKEN leaked into workflow artifacts by Adept's remoteBuild.yml (snapshot of AdeptLanguage/Adept @ 6a64554)
PoC: CVE-2026-83548-SonicWall-SMA1000-Analysis
Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.
PoC: CVE-2024-21546
This repository contains security assessment tooling, detection templates, and an automated exploit toolkit for identifying and exploiting Unauthenticated Remote Code Execution (RCE) in applications utilizing the `UniSharp/laravel-filemanager` package (Versions `< 2.9.1`).
PoC: CVE-2026-78071
Stored XSS via Location Title in DPCalendar Free
PoC: CVE-2026-78070
SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2
PoC: CVE-2026-19949
CVE-2026-19949 - Draft or TODO
PoC: CVE-2026-59822
CVE-2026-59822 - Draft or TODO
PoC: struts2-tool
Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool
PoC: gha-lab-becf103a54
Authorized security-research reproduction of CVE-2025-15617 (GHSA-6xqr-4q5g-xc7x): artipacked GITHUB_TOKEN leak in wazuh FIM Windows integration workflow artifacts
PoC: CVE-2025-9974
Proof of Concept code for the CVE-2025-9974 affecting Nokia Beacon routers.
PoC: tfo-connect-bypass
Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)
PoC: CVE-2026-38577-by-deepak-Anmol
CVE-2026-38577
PoC: gha-lab-23db52563c
Security-research lab: reproduction of CVE-2025-10894 (PR-title injection in GitHub Actions) — snapshot of nrwl/nx
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free