
cve-2026-20896-gitea-poc
CVE-2026-20896 Gitea Docker X-WEBAUTH-USER auth bypass checker

CVE-2026-20896 Gitea Docker X-WEBAUTH-USER auth bypass checker

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication

Generates WebP images that trigger CVE-2023-4863 heap buffer overflow in libwebp, using tunable OFFSET/VALUE constants for exploit testing and…

X-Ways Acropalypse extension detects CVE-2023-21036 in common images


Integer overflow in Apple ImageIO WebP parsing (macOS/iOS)

Proof-of-Concept for CVE-2024-52005: ANSI escape sequence injection in Git. Demonstrates incorrect 'not_affected' VEX claims in hardened container…


the task from C*****k

Let's control Secure Boot Chain ourselves.

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

This exploit targets CVE-2019-14811 in GS environments where PostScript output is not reflected, but is executed such as PDF previews via png images.

CVE-2017-8291 CTF with docker and examples


The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is…