Replication Integrity Bypass via Lua `redis.set_repl(REPL_NONE)` Enables Silent Data Corruption and Persistent Backdoor Functions on Aiven Managed Valkey
Valkey replication stealth path bypasses listpack validation.
Read the writeup →Vulnerability research, detection engineering, and applied cryptography.
Valkey replication stealth path bypasses listpack validation.
Read the writeup →MySQL binlog ACL bypass surfaces replication credentials.
Read the writeup →aiven_gatekeeper extension bypassed via implicit-cast-driven shadow functions.
parse_ident without schema qualification inside SECDEF: variant of CVE-2025-31480 territory.
Autovacuum executes attacker-defined function under the SECURITY_RESTRICTED bypass path.
Read the writeup →ASLR leak through replication metadata.
Read the writeup →SECURITY DEFINER + dblink loopback chain reaches an unrestricted superuser session.
Read the writeup →Postgres CREATE SUBSCRIPTION executes under session_user=postgres, escalating sandboxed user to superuser context.
Karapace REST proxy accepts gzip-compressed messages and decompresses without bounds.
Read the writeup →Unbounded allocation in Dragonfly's stream RESTORE path.
Read the writeup →Single SELECT JSONMergePatch(...) SIGSEGVs the managed instance. Crash payload is storable in shared tables.
Cross-project access to SQL optimizer artifacts via predictable object IDs.
Read the writeup →403 vs 404 oracle on /v1/project/<name> enumerates the entire managed-services customer base.
/v1/userauth timing differential distinguishes registered vs unregistered emails.