
HttpRemotingObjRefLeak
Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Dockerized PoC environment for CVE-2022-22980 (Spring Data MongoDB SpEL injection) with a working exploit demonstrating remote code execution via…

Proof-of-concept exploit for CVE-2024-38475 targeting Apache HTTP Server mod_rewrite improper escaping, enabling URL-to-filesystem mapping for code…

Proof-of-concept exploit for CVE-2025-3248, a remote code injection vulnerability in Langflow prior to 1.3.0. Sends crafted HTTP requests to execute…

Proof-of-concept exploit for CVE-2018-1273, a Spring Data Commons property binder vulnerability leading to remote code execution via crafted HTTP…

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header…

PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the…

CVE-2026-44789 — n8n <1.123.43 HTTP Request pagination prototype pollution to RCE (NODE_OPTIONS runner-spawn gadget). Lab + automated PoC, verified…

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints…

Proof-of-concept exploit for CVE-2025-25014: Prototype pollution in Kibana enabling arbitrary code execution via crafted HTTP requests to ML and…

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

Critical heap buffer overflow vulnerability in the handle_trace_request and parse_trace_request functions of the Fluent Bit HTTP server.

Proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) targeting Java Spring Framework applications via crafted HTTP requests.