
EXPLOIT-CVE-2026-42559
Docker lab + Python PoC for CVE-2026-42559 - DNS rebinding via unvalidated Host header in the rmcp (Rust MCP SDK) Streamable HTTP server transport

Docker lab + Python PoC for CVE-2026-42559 - DNS rebinding via unvalidated Host header in the rmcp (Rust MCP SDK) Streamable HTTP server transport

Stored XSS via User-Agent in Admin Order View in PhocaCart

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)

Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)

Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

Reproducer for CVE-2026-48204: Apache Camel camel-mongodb-gridfs gridfs.* header injection overriding the GridFS operation (enumerate/read/delete…

PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and…

PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header…

PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the…

Reproducer for CVE-2026-46453 — Apache Camel camel-elasticsearch-rest-client unprefixed-header injection (operation/query override via inbound HTTP…

PoC exploit for CVE-2021-40346: HAProxy integer overflow enabling HTTP request smuggling and ACL bypass. Includes analysis, reproduction steps, and…

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

CVE-2026-42945 Nginx Rift

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

Proof-of-concept exploit for CVE-2026-21710, a Node.js HTTP request handling flaw causing uncaught TypeError via __proto__ header, leading to denial…