
BlockChainConstruction
BlockChain Security Construction

BlockChain Security Construction

Controlled security-research lab reproducing CVE-2024-45798 (GHSA-h52q-xhg2-6jw8) in espressif/arduino-esp32 — poisoned-artifact pwn request via…

Tracking the nginx CVE-2026-9256 rewrite-module heap overflow

Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape

Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free

Tracking OVSwrap (CVE-2026-64531), the Open vSwitch datapath netlink overflow

Tracking Copy Fail (CVE-2026-31431), the Linux algif_aead privilege escalation

Tracking PinTheft (CVE-2026-43494, CVE-2026-43502), the RDS zerocopy double-free privilege escalation

Tracking CIFSwitch (CVE-2026-46243), the CIFS cifs.spnego key-origin privilege escalation

CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.

Technical analysis and educational documentation of CVE-2026-7482, a critical heap buffer over-read in Ollama's GGUF loader, including exploitation…

Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d

Documents a structured, repeatable threat hunting methodology covering triggers, SMART hypotheses, feasibility gates, scoping, hunt plans, and…