
CVE-2026-67182-HTTP-Request-Smuggling-Enables-Front-End-Access-Control-Bypass-rouille-
Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)

Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)

PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full…

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

Educational evercookie demo showing how browser storage and HTTP cache techniques can persistently re-identify a visitor.

Exploit for CVE-2021-31166 targeting HTTP Protocol Stack RCE in Windows 10 and Server versions 2004/20H2, enabling remote code execution via crafted…

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

SSRF via smtplib raw TCP sockets bypassing HTTP blocklist in AutoGPT SendEmailBlock

One zero-byte QUIC packet is enough to desynchronize HAProxy's backend connection pool and smuggle HTTP requests across unrelated users — even users…

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

Oracle Fusion Middleware Oracle HTTP Server / WebLogic Server Proxy Plug-in has an easily exploitable, unauthenticated, network-reachable flaw…

This Python script is a Proof-of-Concept (PoC) scanner for detecting the vulnerability CVE-2024-40898, which affects Apache HTTP Server’s SSL…

Zeek package detecting Apache HTTP Server path traversal/RCE exploits (CVE-2021-41773, CVE-2021-42013) with payload capture and server header…

Proof-of-concept exploit for CVE-2024-20404 demonstrating SSRF in Cisco Finesse web-based management interface to enumerate local services by sending…

Windows-based C++ network scanner that fingerprints Cisco SD-WAN/vManage services and checks for CVE-2026-20127 exposure via HTTP endpoint analysis.

Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)

Proof-of-concept exploit for TYPO3 v7.6.15 unencrypted login request vulnerability (CVE-2017-6370), demonstrating plaintext credential exposure over…