
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Validation of best practices in your Kubernetes clusters

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Peirates - Kubernetes Penetration Testing tool

Proof of concept code for Datadog Security Labs referenced exploits.

Run iOS apps without actually installing them!

Exploits CVE-2026-41567 Docker escape using trojanized xz/unpigz binaries to gain a root shell on the host from inside a container.

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark


PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker +…

CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape

PoC for Docker `docker cp` arbitrary file write, exploiting symlink and tar extraction flaws to overwrite host binaries or launch agents for…

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP

Proof-of-concept exploit for CVE-2026-5555, demonstrating container escape via /proc/self/fd symlink in rshared volumes to overwrite host files and…