
Alibab-Nacos-Unauthorized-Reset-PWD
Alibab-Nacos-Unauthorized-Reset PWD

Alibab-Nacos-Unauthorized-Reset PWD

CVE-2026-31816 - Budibase Authentication Bypass to RCE

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

Proof-of-concept for CVE-2026-59243 demonstrating JWT signature bypass in Apache Airflow FAB Auth Manager's Azure AD OAuth callback due to insecure…

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

Proof-of-concept exploit for CVE-2026-11102 demonstrating OAuth2 implicit grant fragment hijacking via unvalidated redirect_uri, leading to access…

SecureCivic is a citizen-built, open source identity verification platform designed for SSA adoption. It replaces private data brokers with a secure,…

Temporary WordPress plugin requiring authentication for the Core REST Batch API endpoint to mitigate the wp2shell vulnerability chain…

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)

Post-quantum hybrid encryption library combining X25519 + ML-KEM-768 with AES-256-GCM

OAuth 2.0 client library for Kit applications supporting authorization code, PKCE, client credentials, and refresh token flows with built-in provider…

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak