
CVE-2026-0915-json-Patch.-V2.0
Provides a security patch for CVE-2026-0915, adding strict JSON schema validation, input sanitization, and rate limiting to prevent injection and DoS…

Provides a security patch for CVE-2026-0915, adding strict JSON schema validation, input sanitization, and rate limiting to prevent injection and DoS…

Proof-of-concept exploit for CVE-2026-42231, a critical prototype pollution vulnerability in n8n XML webhooks leading to remote code execution.…

Proof-of-concept for CVE-2026-25940 demonstrating embedded JavaScript execution via crafted AcroForm radio button appearances in PDF viewers, with…

Technical analysis and Proof-of-Concept (PoC) for a critical Path Traversal vulnerability via Symlink manipulation in the Node.js 'tar' package…

Exploit for CVE-2026-39363, a Vite Dev Server WebSocket arbitrary file read vulnerability, with Python and Node.js scripts for automated exploitation…

Proof-of-concept exploit for CVE-2026-41242 in a Node.js web application, demonstrating the vulnerability and potential impact.

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Demonstrates CVE-2026-3030 prototype pollution in a Node.js JSON merge patch REST API, including a vulnerable server and exploit script for privilege…


CVE‑2025‑55182 Detection

POC for CVE-2025-55130

CVE-2024-27983 this repository builds up a vulnerable HTTP2 Node.js server (`server-nossl.js`) based on CVE-2024-27983 which exploits a continuation…

Documentation of CVE-2017-11499: a hash flooding remote DoS vulnerability in Node.js caused by constant HashTable seeds, with analysis of the attack…

Node.js proof-of-concept exploit for CVE-2016-4971, demonstrating wget FTP redirect filename trust vulnerability with a simple HTTP server.

Working exploit for CVE-2025-23167 – HTTP request smuggling in vulnerable Node.js 20.x versions before 20.19.2

Node.js library for streaming files as HTTP responses with support for partial content, conditional requests, and configurable caching headers.…