Report: Autovacuum Arbitrary Code Execution via Expression Index Shadow Functions
Autovacuum executes attacker-defined function under the SECURITY_RESTRICTED bypass path.
Read the writeup →Vulnerability research, detection engineering, and applied cryptography.
Autovacuum executes attacker-defined function under the SECURITY_RESTRICTED bypass path.
Read the writeup →ASLR leak through replication metadata.
Read the writeup →ONVIF RTSP-over-WebSocket endpoint accessible without authentication.
Read the writeup →IPv6-mapped IPv4 (::ffff:127.0.0.1) bypasses the IPv4-only loopback filter on httptest.cgi.
SECURITY DEFINER + dblink loopback chain reaches an unrestricted superuser session.
Read the writeup →Postgres CREATE SUBSCRIPTION executes under session_user=postgres, escalating sandboxed user to superuser context.
dnsupdate.cgi delete path skips the input validation applied to add.
Karapace REST proxy accepts gzip-compressed messages and decompresses without bounds.
Read the writeup →Unbounded allocation in Dragonfly's stream RESTORE path.
Read the writeup →Single SELECT JSONMergePatch(...) SIGSEGVs the managed instance. Crash payload is storable in shared tables.
pingtest.cgi skips the camera's own validateaddr helper.
SNMP community strings returned in the viewer-role config endpoint.
Read the writeup →Eight findings against the open-source Fireblocks MPC-CMP implementation, P1-P4.
Read the writeup →