
cve-2013-4660_PoC
Proof-of-concept exploit for CVE-2013-4660 demonstrating YAML deserialization remote code execution in a Dockerized Node.js environment with…

Proof-of-concept exploit for CVE-2013-4660 demonstrating YAML deserialization remote code execution in a Dockerized Node.js environment with…

Docker Container Escape POC via mlx-metal importlib

The code for personally reproducing the corresponding vulnerability

CVE-2018-16509 Docker Playground - Ghostscript command execution

Proof-of-concept for Docker Desktop for Windows privilege escalation (CVE-2020-11492). Exploits named pipe impersonation to achieve SYSTEM-level…

OPA Gatekeeper-based policy templates to mitigate CVE-2020-8554 by restricting Kubernetes Service external IPs to an allow list, preventing traffic…

CVE-2025-59376, CVE-2025-59377

CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script

Working exploit for CVE-2024-21626, a runC/Docker container escape via working directory symlink attack, enabling host filesystem access.

Docker base image with backported Host header validation fix for CVE-2025-12543 in Undertow 1.4.x, enabling secure deployment of WildFly 11…

DaemonSet с реализацией временной меры для митигации уязвимости Copy Fail (CVE-2026-31431)

Detection script for CIFSwitch - CVE-2026-46243

CVE-2024-10220 Test repo

DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"

This is a container built for demonstration purposes that has a version of the sudo command which is vulnerable to CVE-2019-14287

Companion source for YouTube video "Stop Mounting docker.sock — Run Trivy Without Giving Away Root Access — (inspired by CVE-2026-33634)"

PoC for CVE-2024-21626: runc leaks an internal fd referencing the host CWD before pivot_root, enabling container escape by setting process.cwd to…

kali-linux-docker