
Serverless-Top-10-Project
OWASP Serverless Top 10
cloud-securitycurated-resourceseducation+3
218

OWASP Serverless Top 10

Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities

OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks…

Docker lab reproducing the FOSSBilling pre-auth RCE chain (CVE-2026-27604 auth bypass + CVE-2026-28496 Twig SSTI) with a Python PoC and patched…