
patch-CVE-2026-14290
Patch: Command injection in GlobalProtect (Palo Alto PAN-OS)

Patch: Command injection in GlobalProtect (Palo Alto PAN-OS)

Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.

Companion source for YouTube video "Stop Mounting docker.sock — Run Trivy Without Giving Away Root Access — (inspired by CVE-2026-33634)"

Ansible role to patch RHSB-2022-001 Polkit Privilege Escalation - (CVE-2021-4034)

Patch: Privilege escalation via web UI (Cisco IOS XE)

Security risk analysis for Kubernetes resources

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

Kubernetes DaemonSet that hot-patches JVMs to mitigate Log4j2 vulnerabilities (CVE-2021-44228, CVE-2021-45046) by disabling JNDI lookups, providing…

Docker mitigation for CVE-2026-31431 ('Copy Fail'). Includes Kubernetes templates as well.

This repository contains BigFix Content that I created for identifying the AlmaLinux systems that require patching to remediate CVE-2026-31431

Linting tool for CloudFormation templates

A powerful testing tool for Kubernetes clusters.

Patched Log4j 1.2.17 library with the vulnerable JMSAppender class removed to mitigate CVE-2021-4104, intended as a drop-in replacement for affected…

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

Salt state to deploy a mitigation of the copy.fail vulnerability (CVE-2026-31431)

Read-only checker for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) Linux kernel local-root vulns

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

Security-hardened fork of OpenCode - Fixes CVE-2026-22812 (CVSS 8.8 RCE) that upstream refuses to patch