
freddy
Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Discover input surfaces and security issues in compiled .NET assemblies — without running them.

Fuzzing Framework for Modules in Apache HTTPD Server

Critical heap buffer overflow vulnerability in the handle_trace_request and parse_trace_request functions of the Fluent Bit HTTP server.


Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the…

PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header…

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)

Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

CVE-2017-12615 - Apache Tomcat Remote Code Execution (RCE)

CVE-2026-44789 — n8n <1.123.43 HTTP Request pagination prototype pollution to RCE (NODE_OPTIONS runner-spawn gadget). Lab + automated PoC, verified…