
obike
Reverse engineering of the oBike protocol communication (BLE and HTTP)

Reverse engineering of the oBike protocol communication (BLE and HTTP)

A coverage-guided REST API fuzzer developed on top of LibAFL

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

OPNsense GUI, API and systems backend

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

a PE Loader and Windows API tracer. Useful in malware analysis.

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch


Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)