
wolfssl
Lightweight TLS 1.3/DTLS 1.3 library with FIPS 140-3 validated cryptography, hardware entropy support, and post-quantum cipher suites for embedded,…

Lightweight TLS 1.3/DTLS 1.3 library with FIPS 140-3 validated cryptography, hardware entropy support, and post-quantum cipher suites for embedded,…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the…

Simple and flexible tool for managing secrets

C library implementing W3C XML Signature and XML Encryption standards for secure XML document signing, verification, and encryption in applications.

PoC toolkit that unpacks router firmware, decrypts device secrets, forges JWT tokens, and exploits CVE-2026-71960/71961 to take over Cudy WR3000 mesh…

Open-source platform for secrets, certificates, and privileged access management with secret scanning, dynamic secrets, PKI, and CI/CD integrations.…

Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Rewe API reverse engineering in Go

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…


Open source identity verification platform with tokenized SSNs, zero-knowledge proofs, and real-time fraud detection. Provides secure API gateway for…

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.