
kubernetes-client__java_CVE-2020-8570_client-java-parent-9_0_2_fixed
Java client library for the Kubernetes API, enabling programmatic management of clusters, pods, deployments, and other resources with support for…

Java client library for the Kubernetes API, enabling programmatic management of clusters, pods, deployments, and other resources with support for…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Educational Docker-based lab demonstrating the Heartbleed bug (CVE-2014-0160) with hacker, victim, and server containers for hands-on exploitation…

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

Kubernetes policy engine with OPA-based admission control, mutation, and audit for enforcing security and compliance configurations.

Proof of Concept code for proving CVE-2024-40635 vulnerability

CVE-2022-42889 (a.k.a. Text4Shell) RCE Proof of Concept

Red Team K8S Adversary Emulation Based on kubectl

A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

Proof-of-concept and educational report demonstrating local privilege escalation to root via default LXD group membership on Ubuntu Server, with…

Give coding agents a disposable Linux VM, not your laptop


CVE-2019-5736 POCs

BPF-LSM mitigation for CVE-2026-31431 (Copy Fail) — denies AF_ALG socket creation cluster-wide

Docker CVE-2022-37708

Remote Code Execution in LocalStack 0.12.6