

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

CVE-2019-5736 POCs

Docker CVE-2022-37708

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free…

A structured explanation of CVE-2026-31431 (Copy Fail), connecting the three kernel changes that introduced the vulnerability and enabled its…

CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The…

Proof-of-concept exploit for CVE-2019-5736, a container escape vulnerability in runc, demonstrating the attack and enabling security testing.

Writeup of CVE-2017-1002101 with sample "exploit"/escape

Modified version of CVE-2019-5736-PoC by Frichetten

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Proof-of-concept for CVE-2024-21626, a runc container escape vulnerability. Includes verification scripts, two exploitation methods (cron reverse…

In this project, we found a recent attack through the malicious container and implemented a security mechanism to stop it.

非常简单的CVE-2023-0386's exp and analysis.Use c and sh.

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…