
CVE-2026-21876 PoC: WAF charset bypass (Flask, ASP.NET and Spring Boot stands)
CVE-2026-21876 docker container + minimal PoC.
I would like to thank @airween and @fzipi separately for their quick response! The vulnerability fix was ready in a very short time.
Run:
cd springboot_undertow_stand # or aspnet_stand
docker compose up --build
python3 demo/send.py # BASELINE -> 403, BYPASS -> 200 + reconstructed payload