
bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)

🛡️ Open-source and cloud-native Web Application Firewall (WAF)


Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

React2Shell (CVE-2025-55182) – An intentionally vulnerable Next.js application created for educational and research purposes.

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

Log4Shell CVE-2021-44228 mitigation tester


A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

Apache HTTP Server 2.4.50 - RCE Lab


Log4Shell (CVE-2021-44228) docker lab