
PoC: identify silent security patches before CVE
VCamper ("Version Camper") is a proof-of-concept CLI that reviews a Git commit range for likely silent security fixes.
Security fixes often reach public Git history before the advisory trail catches up. A maintenance-looking commit can carry enough evidence for a reviewer to infer the bug path and likely consequence.
VCamper turns that release-diff workflow into repeatable evidence collection. It gathers each candidate's patch and changed-file snapshots. It records a hotspot plan before asking an agent to screen and verify the commits most likely to matter.
Follow updates: x.com/rndhouse
curl fixed CVE-2025-0725 in commit 76f83f0db23846e254d940ec7fe141010077eb88. The title content_encoding: drop support for zlib before 1.2.0.4 reads like compatibility maintenance. The fix landed in curl's GitHub repo on 2025-01-24 through PR #16079. curl published the advisory on 2025-02-05. That left about 12 days between public code and public advisory. Sources: curl advisory and curl PR #16079.
This command analyzes that fix commit by itself:
cargo run -- analyze \
--repo /path/to/curl \
--from 76f83f0db23846e254d940ec7fe141010077eb88 \
--to 76f83f0db23846e254d940ec7fe141010077eb88 \
--provider codex \
--model gpt-5.4 \
--screen-effort medium \
--verify-effort high \
--out /tmp/vcamper-curl-cve-2025-0725
VCamper flagged the commit as security-relevant with confidence 0.95. The finding traced the removed old-zlib gzip fallback to a remote client-side memory exhaustion path: a server could keep curl buffering attacker-controlled gzip header bytes until memory was exhausted. The verifier identified the relevant state as GZIP_UNDERFLOW; optional gzip header fields could keep missing their terminating NUL while curl kept reallocating and appending bytes to z->next_in.
The run used the public fix commit alone; the CVE text stayed out of the analysis. The finding matched the vulnerable old-zlib fallback path and reported the supported consequence as remote resource-consumption DoS. curl's advisory uses the broader CWE-680 classification.
wolfSSL fixed CVE-2026-5194 in commit abce5be989ccd0665e2b9445abb856886975dfd1 from PR #10131. The commit title was 20260403-WC_FIPS_186. This is a harder case than curl because the patch mixes FIPS 186 compliance work with test and verification changes. It touches ASN.1 and ECC code in wolfcrypt/src/. It also reaches TLS and PKCS#7 paths.
That commit shows why VCamper uses staged Codex passes. A broad prompt drifted toward one local bug story. The staged pipeline kept separate theories alive and surfaced three verified findings from the same commit:
signatureAlgorithm / key-family binding flaw in ConfirmSignatureThe composite finalist carries the main signal. The final staged run confirmed a 0.90 finding that signed-object verification let attacker-controlled signature OIDs steer ECDSA verification to mismatched or below-policy digests. The published CVE also emphasizes mixed EdDSA / ML-DSA enablement. VCamper landed in the same patch family. It preserved multiple theories and verified them independently. It also recovered the shared verification boundary.
This command shows the current prototype behavior on that commit:
cargo run -- analyze \
--repo /path/to/wolfssl \
--from abce5be989ccd0665e2b9445abb856886975dfd1 \
--to abce5be989ccd0665e2b9445abb856886975dfd1 \
--provider codex \
--model gpt-5.4 \
--screen-effort xhigh \
--verify-effort xhigh \
--inventory-focuses 0,1,3,4,9 \
--out /tmp/vcamper-wolfssl-cve-2026-5194
That command uses a curated hotspot shortlist because the commit is unusually noisy. The run recovered the relevant patch family and a useful composite signed-object verification theory from a commit that reads like compliance churn. For hard crypto commits the prototype can recover shared trust boundaries. It can also keep multiple verified security stories alive. Closer CVE narrative matching needs stronger mixed-feature reasoning in later stages.
cargo run -- analyze \
--repo /path/to/repo \
--from <older-release-commit> \
--to <newer-release-commit> \
--provider codex \
--model gpt-5.4 \
--screen-effort medium \
--verify-effort high \
--out /tmp/vcamper-run
gitcodexclaude