April 18, 2026PKI / CA constraint bypass
A widely-deployed open-source crypto library enforces an RFC 5280 CA path-length constraint only when a separate extension is present, so a CA forbidden from delegating can mint rogue sub-CAs the library still trusts. Includes an interactive proof you can run in the browser.
Read the writeup →
April 18, 2026Authz bypass
Mattermost shared-channel invite endpoint enforces system-level perms but not channel-level. Same bug class as CVE-2025-11777.
Read the writeup →
April 17, 2026Methodology
Iteration 3: results and what would not be a finding.
Read the writeup →
April 17, 2026Methodology
Iteration 2: parser audit and candidate ranking.
Read the writeup →
April 17, 2026Methodology
Recon and variant-seed inventory against sequoia-openpgp based on its historical RUSTSEC advisories.
Read the writeup →
April 17, 2026Methodology
Root-cause walk-through of CVE-2025-47934 (signature-verification bypass via msg.packets mutation) and a variant search against the v6.2.0 compression refactor.
Read the writeup →
April 17, 2026Methodology
Top-to-bottom audit log of systemd-coredumpd and systemd-resolved DNS parser. No findings; the writeup is the methodology and the dead ends.
Read the writeup →
April 16, 2026Consensus stall
QBFT's HasBadProposal check is symmetric across the round, one prepared bad proposal halts the round for every validator.
Read the writeup →
April 16, 2026DoS / unauth
N-day demonstration of CVE-2024-32972 against an unpatched go-ethereum fork. Single unauthenticated TCP packet causes 7.8 GB allocation, OOM-kills the node. Targeting all IBFT validators halts the entire chain.
Read the writeup →
April 15, 2026DoS / data integrity
Valkey replication stealth path bypasses listpack validation.
Read the writeup →
April 15, 2026Info disclosure
MySQL binlog ACL bypass surfaces replication credentials.
Read the writeup →
April 14, 2026Sandbox bypass
aiven_gatekeeper extension bypassed via implicit-cast-driven shadow functions.
Read the writeup →
April 14, 2026Privilege escalation
parse_ident without schema qualification inside SECDEF: variant of CVE-2025-31480 territory.
Read the writeup →