
CVE-2023-31606
Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Linting tool for CloudFormation templates

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

A security scanner for your LLM agentic workflows

👮 👊 RegEx Denial of Service (ReDos) Scanner

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

A list of awesome penetration testing tools and resources.

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

A static analysis tool for securing Go code

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.