
CVE-2026-44848-PoC
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Security research — PoC for local root privilege escalation on macOS Mavericks 10.9.

Evaluates password strength based on length, character types, and diversity, and verifies against data breaches via the Have I Been Pwned API, with…

PoC | NextJS Middleware 15.2.2 - Authorization Bypass

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

Automates JWT token hijacking by exploiting CVE-2018-0114, generating attacker RSA keys and injecting them into the JWT header to forge valid tokens.

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

This repository discloses a server-side authorization bypass in Instagram, which allowed unauthenticated access to private timelines; it seems likely…

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…