
EXPLOIT-CVE-2026-42559
Docker lab + Python PoC for CVE-2026-42559 - DNS rebinding via unvalidated Host header in the rmcp (Rust MCP SDK) Streamable HTTP server transport

Docker lab + Python PoC for CVE-2026-42559 - DNS rebinding via unvalidated Host header in the rmcp (Rust MCP SDK) Streamable HTTP server transport

Python test client that sends HTTP GET requests with oversized Authorization headers to trigger header-parsing bugs like CVE-2025-4476. For…

Proof-of-concept exploit for CVE-2026-21710, a Node.js HTTP request handling flaw causing uncaught TypeError via __proto__ header, leading to denial…

Proof-of-concept demonstrating SSRF and HTTP header injection in KubePlus ResourceComposition, enabling cloud metadata access and IAM credential…

Proof-of-concept for CVE-2021-40346, demonstrating HTTP request smuggling in HAProxy via integer overflow, with Docker-based environment to bypass…

Stored XSS via User-Agent in Admin Order View in PhocaCart

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)

Demonstrates CVE-2022-31813 Apache HTTP Server bypass using X-Real-IP header manipulation to evade access controls, with a Docker-based test…

PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the…

PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header…

PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and…

poc for cve-2025-53772

Tenda f3 Malformed HTTP Request Header Processing Vulnerability.

Reproducer for CVE-2026-48204: Apache Camel camel-mongodb-gridfs gridfs.* header injection overriding the GridFS operation (enumerate/read/delete…

Reproducer for CVE-2026-46453 — Apache Camel camel-elasticsearch-rest-client unprefixed-header injection (operation/query override via inbound HTTP…

CVE-2026-42945 Nginx Rift

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…