
CVE-2026-40345
Reproduces a stack-exhaustion denial-of-service in deepmerge-ts before 8.0.0, documents exploitation, and includes a scanner for vulnerable…

Reproduces a stack-exhaustion denial-of-service in deepmerge-ts before 8.0.0, documents exploitation, and includes a scanner for vulnerable…

Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model…

spring retry 1.3.x fix with niche toolkit for CVE-2026-41710

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.


A Java helper to identify log4j in the current classpath

Shell injection in Rebar3

VEX Repository Specification

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

Octoscan is a static vulnerability scanner for GitHub action workflows.

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)


OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider
