
CVE-2026-42536-PoC
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content

Stored XSS via User-Agent in Admin Order View in PhocaCart

Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)

Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Firmware security analysis of BD Alaris 8015 infusion pump (CVE-2016-9355). Identified 6 compound vulnerabilities including plaintext Wi-Fi…

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Reproducible AI-assisted vulnerability rediscovery of CVE-2026-42945 in nginx, including technical analysis, PoC trigger, and patch validation for…


Technical analysis of CVE-2026-24072, a local privilege escalation in Apache HTTP Server mod_rewrite, including root cause, patches, and Dockerized…

One zero-byte QUIC packet is enough to desynchronize HAProxy's backend connection pool and smuggle HTTP requests across unrelated users — even users…

Minimal reproduction of CVE-2026-22732 — Spring Security HTTP headers silently dropped

Proof-of-concept exploit for CVE-2025-69219, demonstrating remote code execution in Apache Airflow Providers HTTP via unsafe pickle deserialization.…

Technical research paper analyzing CVE-2024-38476, a critical Apache HTTP Server vulnerability enabling SSRF, information disclosure, and potential…

Proof-of-concept exploit for CVE-2025-55182, a remote code execution vulnerability in React Server Functions (Next.js). Demonstrates prototype…

An issue was discoverd in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive…