
CVE-2026-76564
Stored XSS via User-Agent in Admin Order View in PhocaCart

Stored XSS via User-Agent in Admin Order View in PhocaCart

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)

PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the…

PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header…

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)