## Vulnerability Details **File**: `backend/s3/s3.go` **Lines**: 1359-1380 (functions `s3CheckRedirect` / `s3RedirectCrossesHost`) ### Root Cause Commit `e7b1eb774` (released in v1.74.3) added a `CheckRedirect` policy for the S3 HTTP client whose purpose is to strip the `X-Amz-Security-Token` header (the AWS STS session token) whenever a redirect chain "crosses a host", so the token isn't forwarded to an unintended origin. `s3RedirectCrossesHost` decides this purely by comparing `url.URL.Host` (hostname[:port]); it never looks at `url.URL.Scheme`. A redirect that keeps the exact same host:port but changes the scheme from `https://` to `http://` therefore compares as "same host" and `X-Amz-Security-Token` is *not* stripped — it is sent again, this time over plaintext HTTP. ```go func s3RedirectCrossesHost(req *http.Request, via []*http.Request) bool { if len(via) == 0 { return false } host := via[0].URL.Host for _, redirect := range via[1:] { if redirect.URL.Host != host { return true } } return host != req.URL.Host } ``` ### Attack Scenario 1. The user configures an `s3` remote (or `--s3-endpoint` pointing at a self-hosted/third-party S3-compatible service) using temporary credentials that include an STS `session_token` (common for assumed-role / CI / Kubernetes IRSA setups). 2. The configured endpoint responds to a request with a 3xx redirect to the *same* host:port but with `http://` instead of `https://` (TLS-front misconfiguration, maintenance redirect, or a malicious/compromised storage provider trying to harvest the token). 3. rclone's S3 HTTP client follows the redirect and re-sends the request, including `X-Amz-Security-Token`, over the now-unencrypted connection to that same host. 4. Any passive observer on that now-plaintext network path can read the STS session token from the request headers. ### Impact Disclosure of the AWS STS session token (`X-Amz-Security-Token`) in cleartext for the remainder of its validity window. This is the exact class of leak that `e7b1eb774` was written to close — it just doesn't cover the scheme-downgrade axis of "crossing a host". ### Vulnerable Code ```go func s3RedirectCrossesHost(req *http.Request, via []*http.Request) bool { if len(via) == 0 { return false } host := via[0].URL.Host for _, redirect := range via[1:] { if redirect.URL.Host != host { return true } } return host != req.URL.Host } ``` ### Recommended Fix Also compare `URL.Scheme`, so a scheme downgrade on the same host is treated the same as a host change: ```go func s3RedirectCrossesHost(req *http.Request, via []*http.Request) bool { if len(via) == 0 { return false } scheme, host := via[0].URL.Scheme, via[0].URL.Host for _, redirect := range via[1:] { if redirect.URL.Host != host || redirect.URL.Scheme != scheme { return true } } return host != req.URL.Host || scheme != req.URL.Scheme } ``` ### Verification Added a unit test (`backend/s3/redirect_scheme_test.go`) that calls the real, unmodified `s3RedirectCrossesHost` / `s3CheckRedirect` with an `https://bucket.example.com` -> `http://bucket.example.com` redirect chain. On unpatched code (commit 16091ce365, current master / v1.74.3): - `s3RedirectCrossesHost` returns `false` - `s3CheckRedirect` leaves `X-Amz-Security-Token: SECRET-SESSION-TOKEN` intact on the outgoing (plaintext) request. ``` === RUN TestSchemeDowngradeNotDetectedAsCrossHost redirect_scheme_test.go:23: initial=https://bucket.example.com final=http://bucket.example.com s3RedirectCrossesHost=false --- PASS: TestSchemeDowngradeNotDetectedAsCrossHost (0.00s) ``` After applying the one-line fix above (also adding scheme comparison), the token is correctly stripped and all existing redirect tests (`TestClientRemovesSecurityTokenOnCrossHostRedirect`, `TestClientDoesNotRestoreSecurityTokenAfterCrossHostRedirect`, `TestClientKeepsSecurityTokenOnSameHostRedirect`, `TestClientStopsAfterTenRedirects`) continue to pass. A minimal fix commit is ready and can be pushed to a private fork once this report is acknowledged.
PoC: YellowKey-BitLocker-CVE-2026-45585
YellowKey BitLocker recovery - bitlocker yellowkey, yellowkey bitlocker, CVE-2026-45585, yellowkey github, yellowkey vulnerability, yellowkey CVE, TPM, BitLocker recovery key backup, Windows 10/11, CLI GUI, portable audit tool. Download:🡇
PoC: Keycloak_CVE-2026-18963_PoC
This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).
PoC: CVE-2026-18963-keycloak
CVE-2026-18963
PoC: pixel-ksu-root
adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.
PoC: CVE-2026-43914-PoC
PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.
PoC: CVE-2026-72898
Metabase SQLi
PoC: CVE-2026-19478
GitLab Code injection
PoC: CVE-2026-75604
CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing
PoC: CVE-2026-19632
CVE-2026-19632 - TranslatePress One-Day PoC
PoC: CVE-2026-56705
CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.
PoC: CVE-2026-75604-poc
CVE-2026-75604 Next.js Windows RCE poc
PoC: CVE-2026-4692-trust-me-im-in-rdm
Firefox BrowsingContext field-sync authz bypass (N-day, bug 2017643): forged PContent::CommitBrowsingContextTransaction sets InRDMPane=true from a compromised content process - parent applies it. Prerequisite primitive for privileged-UI touch-event injection.
PoC: CVE-2022-28906-POC
CVE-2022-28906 Proof of concept in Python3
PoC: CVE-2026-41551
ROS# 路径遍历漏洞(CVE-2026-41551)
PoC: cve-2022-42475-poc
Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability affecting the SSL-VPN service in certain versions of FortiOS.
PoC: CVE-2026-15469
CVE-2026-15469 — Hard-coded RSA-512 mesh group private key in TP-Link Deco XE75/XE5300/WE10800 (CWE-321). Advisory, analysis & PoC methodology (EN/KO).
PoC: CVE-2026-32475-PoC
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
PoC: CVE-2026-12295-UXXS-in-my-wasm
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim origin (UXSS), via mojo-port send-path injection from a compromised content process
PoC: CVE-2026-74939-escape-the-mac-n-cheese-box
Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement, via mojo-port send-path injection from a compromised content process
PoC: Project-CVE-2026-33017
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
PoC: CVE-2026-70463
Testing CVE-2026-70463 by Fyyre
PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report
Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.
PoC: CVE-2026-20131-Post-Incident-Written-Report
Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.
PoC: ghostlock-pfem10
GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes
PoC: htb-labs-connected
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
PoC: spring-ai-sibling-loop-poc
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
PoC: mssharepoint-scanner
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
PoC: weblogic
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
PoC: CVE-2021-27876-veritas-backup
Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)
PoC: rmg-s9180-fzg1
Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM
PoC: hacktivity-vulns-exploits-lab
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
PoC: CVE-2026-55040-Mass-Exploit
CVE-2026-55040
PoC: Project-CVE-2026-75604
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.
PoC: CVE-2026-18963
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
PoC: CVE-2015-3246
CVE-2015-3246
PoC: CVE-2015-5287
CVE-2015-5287
PoC: htb-labs-nexus
Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.
PoC: Cisco-CVE-2026-20303-More
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
PoC: CVE-Ubiquiti
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
PoC: CVE-2026-18431
CVE-2026-18431 - Draft or TODO
PoC: CVE-2026-8467
CVE-2026-8467 - Draft or TODO
PoC: CVE-2026-50787
Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.
PoC: solarview-ics-vulnerability-analysis
Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)
PoC: CVE-2026-72898-metabase-sqli
Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)
PoC: By-Poloss..-..CVE-2026-18080
Poc CVE-2026-18080
PoC: CVE-2026-63520
POC pre-auth RCE on Sharepoint chain
PoC: f_hid-4.14-backports
Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification records.
PoC: chrome-vuln-scanner
Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.
PoC: CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
CVE-2026-19912, CVE-2026-19913, CVE-2026-19914
PoC: CVE-2026-19632-POC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
PoC: ghostlock-infinix-hot70
Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.
PoC: CVE-2025-2945-pgAdmin-RCE
PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9
PoC: CVE-2026-63072
CVE-2026-63072
PoC: CVE-2026-76904
PostGIS SQL Injection GeoTools
PoC: CVE-2014-085
ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场
PoC: hdwebmobile-photo-video-reviews
WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction
PoC: Exploit-CVE-2026-56705
CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection
PoC: CVE-2026-73570
Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)
PoC: vivo-root-build
vivo/iQOO 提权 so 编译(CVE-2026-43499)
PoC: CVE-2026-72530-TrueConf-Sandbox-Escape-
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.
PoC: CVE-2021-41773-Exploit
CVE-2021-41773 Apache HTTP Server 2.4.49 Path Traversal to RCE Exploit
PoC: cve-2026-60004
CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.
PoC: CVE-2026-68820_Mass_Exploit
CVE-2026-68820 — Mass Exploit Framework Edition.
PoC: CVE-2026-58073-check
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
PoC: CVE-2026-18963
Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.
PoC: CVE-2020-1472
CVE-2020-1472
PoC: CVE-2026-32635-Angular-XSS-Mitigation-
Demostracion educativa de mitigacion y deteccion de CVE-2026-32635: XSS en atributos i18n de Angular.
PoC: CVE-2018-16763_fuel_cms_exploit
A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.
PoC: CVE-2026-26211
Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.
PoC: keycloak-CVE-2026-18963
PoC, Dockerfile playground and root cause from patch diff analysis.
PoC: CVE-2026-17532-lab
CVE-2026-17532 Docker Lab.
PoC: Wildfire
CVE-2026-39154, Stored XSS in CometChat JS SDK
PoC: Trespasser
CVE-2026-74970, Fission site isolation bypass in Firefox WebRender
PoC: Palimpsest
CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)
PoC: SkeletonKey
CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox
PoC: Revenant
CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)
PoC: CVE-2026-73570
PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)
PoC: EDRKiller
Use cve-2026-36425 killer edr,360 can killer
PoC: RootMyVivo
One-click root for vivo/iQOO devices on locked bootloader | CVE-2026-43499 + KernelSU
PoC: Exploit-For-CVE-2026-18963
Exploit for CVE-2026-18963 by BlackHatExploitation
PoC: gha-lab-aaaaa1cc3e
GitHub Actions workflow sandbox for CVE-2025-67727 reproduction
PoC: gha-lab-f1c8785cc8
GitHub Actions workflow sandbox for CVE-2025-46820 reproduction
PoC: CVE-2026-16348
TP-Link Archer BE800 V1 — VPN Key Injection RCE
PoC: CVE-2026-77806
CVE-2026-77806漏洞检测代码
PoC: UniBLEed
Unitree G1 RCE PoC & Scripts (CVE-2026-76639 / CVE-2026-76640) technical details at boschko.ca/g1-ble-rce/
PoC: echidna
Unlock the bootloader of any exploitable device vulnerable to CVE-2021-30327
PoC: gha-lab-227431b300
GitHub Actions workflow sandbox for CVE-2023-30628 (changelog.yml command injection)
PoC: lab-annie
Automates exploitation of CVE-2020-13160, a critical remote code execution vulnerability in AnyDesk 5.5.2.
PoC: gha-lab-5ed08d6a80
GitHub Actions workflow sandbox for CVE-2025-32953 reproduction
PoC: Explotacion-RCE-Pentesting-BlueKeep-CVE-2019-0708-
Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.
PoC: PoC-for-CVE-2025-46359
PoC CVE-2025-46359
PoC: CVE-2026-63039
Reproducer for CVE-2026-63039 (Apache InLong AuditAlertRule MyBatis ORDER BY SQL injection via orderField/orderType)
PoC: CVE-2026-28672
Reproducer for CVE-2026-28672 (Apache Ranger UnixUserGroupBuilder OS command injection via username in the unixusersync module)
PoC: CVE-2026-78329
Reproducer for CVE-2026-78329 (Apache Camel camel-undertow header filter strategy not applied, websocket.* injection) — Camel Spring Boot
PoC: CVE-2026-71300
Reproducer for CVE-2026-71300 (Apache Camel camel-atmosphere-websocket dispatch header injection) — Camel Spring Boot
PoC: CVE-2026-60093
Reproducer for CVE-2026-60093 (Apache Camel camel-azure-storage-datalake downloadToFile path traversal) — Camel Spring Boot + Camel Quarkus
PoC: CVE-2026-66906
Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus
PoC: CVE-2026-66907
Reproducer for CVE-2026-66907 (Apache Camel camel-google-storage downloadFileName path traversal) — Camel Spring Boot + Camel Quarkus
PoC: CVE-2026-66908
Reproducer for CVE-2026-66908 (Apache Camel camel-platform-http-main JWT iss/aud not validated) — standalone camel-main
PoC: CVE-2026-68820-Mitigation-PoC-
Este repositorio contiene una demostración educativa de la mitigación para **CVE-2026-68820**, una vulnerabilidad crítica de tipo **Use-After-Free (UAF)** en el driver `afd.sys` de Windows.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free