
CVE-2026-24072-Analysis
Technical analysis of CVE-2026-24072, a local privilege escalation in Apache HTTP Server mod_rewrite, including root cause, patches, and Dockerized…

Technical analysis of CVE-2026-24072, a local privilege escalation in Apache HTTP Server mod_rewrite, including root cause, patches, and Dockerized…

Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

Detailed write-up and proof of concept for CVE-2023-41717, demonstrating bypass of Zscaler proxy file download/upload restrictions via HTTP Range…

Stored XSS via User-Agent in Admin Order View in PhocaCart

Reverse engineering of the oBike protocol communication (BLE and HTTP)

Reproducible AI-assisted vulnerability rediscovery of CVE-2026-42945 in nginx, including technical analysis, PoC trigger, and patch validation for…

Collections of Orange Tsai's public presentation slides.

Grammar-based HTTP/1 fuzzer with mutation ability

One zero-byte QUIC packet is enough to desynchronize HAProxy's backend connection pool and smuggle HTTP requests across unrelated users — even users…

Technical research paper analyzing CVE-2024-38476, a critical Apache HTTP Server vulnerability enabling SSRF, information disclosure, and potential…

Minimal reproduction of CVE-2026-22732 — Spring Security HTTP headers silently dropped

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)

Firmware security analysis of BD Alaris 8015 infusion pump (CVE-2016-9355). Identified 6 compound vulnerabilities including plaintext Wi-Fi…

Proof-of-concept exploit for CVE-2025-55182, a remote code execution vulnerability in React Server Functions (Next.js). Demonstrates prototype…

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

Proof-of-concept exploit for CVE-2025-69219, demonstrating remote code execution in Apache Airflow Providers HTTP via unsafe pickle deserialization.…