
gate0
A small, auditable, terminating, deterministic micro-policy engine

A small, auditable, terminating, deterministic micro-policy engine

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

An implementation of a vulnerable MCP server using mcp-go

Apache APISIX batch-requests RCE(CVE-2022-24112)

SAML v2.0 bindings in Java using JAXB

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device

Burp Plugin for Secret Matching

Critical Unauthenticated API Access in vBulletin

A PoC exploit for CVE-2020-13945 - Apache APISIX Remote Code Execution (RCE)

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

Vulnerability Research

PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)

PoC exploit for CVE-2026-32621 demonstrating Apollo Federation deepMerge prototype pollution via crafted GraphQL aliases, with patched-version tests.