
BadHost-CVE-2026-48710-Exploit
Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

Research on GraphQL from an AppSec point of view.

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

A deliberately vulnerable web application for learning web application security.

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.

This is a container of web applications that work with OWASP Bug Bounty for Projects

Web and mobile application security training platform

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

A vulnerable version of Rails that follows the OWASP Top 10

Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.