
HTTP3ONSTEROIDS
HTTP3ONSTEROIDS - A research on CVE-2023-25950 where HAProxy's HTTP/3 implementation fails to block a malformed HTTP header field name.

HTTP3ONSTEROIDS - A research on CVE-2023-25950 where HAProxy's HTTP/3 implementation fails to block a malformed HTTP header field name.

Testing POC for use cases

Investigating CVE-2022-36804

CVE-2020-8163 - Remote code execution of user-provided local names in Rails

PoC for CVE-2026-66066 in Ruby on Rails


Enviroment and exploit to rce test


Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

A vulnerable version of Rails that follows the OWASP Top 10

Mountable Rails engine providing 24+ cybersecurity escape room scenarios with randomized passwords, JIT-compiled NPC dialogue, and RESTful API for…

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool
