Forem

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2026-22817: Identity Theft on the Edge: Exploiting JWT Algorithm Confusion in Hono

CVE-2026-22817: Identity Theft on the Edge: Exploiting JWT Algorithm Confusion in Hono

Comments
2 min read
CVE-2026-22785: Orval Overload: From OpenAPI Spec to Remote Code Execution

CVE-2026-22785: Orval Overload: From OpenAPI Spec to Remote Code Execution

Comments
2 min read
đź”’ The Hidden Cost of Dependency Confusion
Cover image for đź”’ The Hidden Cost of Dependency Confusion

đź”’ The Hidden Cost of Dependency Confusion

1
Comments
4 min read
GHSA-F2MF-Q878-GH58: Parsl Tongue: SQL Injection in High-Performance Computing Visualization

GHSA-F2MF-Q878-GH58: Parsl Tongue: SQL Injection in High-Performance Computing Visualization

Comments
2 min read
GHSA-VX9W-5CX4-9796: Crawl4AI: When Web Scrapers Become File Servers

GHSA-VX9W-5CX4-9796: Crawl4AI: When Web Scrapers Become File Servers

Comments
2 min read
CVE-2026-23996: The Tell-Tale Delay: Timing Side-Channels in fastapi-api-key

CVE-2026-23996: The Tell-Tale Delay: Timing Side-Channels in fastapi-api-key

Comments
2 min read
GHSA-RHFX-M35P-FF5J: Borrow Checker's Revenge: Stacked Borrows Violation in Rust's `lru` Crate

GHSA-RHFX-M35P-FF5J: Borrow Checker's Revenge: Stacked Borrows Violation in Rust's `lru` Crate

Comments
2 min read
CVE-2026-21441: The Invisible Avalanche: urllib3 Decompression Bomb

CVE-2026-21441: The Invisible Avalanche: urllib3 Decompression Bomb

Comments
2 min read
CVE-2025-32444: Pickle Rick-Roll: Critical RCE in vLLM's Mooncake Integration

CVE-2025-32444: Pickle Rick-Roll: Critical RCE in vLLM's Mooncake Integration

Comments
2 min read
CVE-2026-22708: Trust Issues: Bypassing Cursor AI's 'Safe Mode' via Shell Built-ins

CVE-2026-22708: Trust Issues: Bypassing Cursor AI's 'Safe Mode' via Shell Built-ins

Comments
2 min read
CVE-2026-22200: Paper Cuts to Pwnage: Turning osTicket PDF Exports into RCE

CVE-2026-22200: Paper Cuts to Pwnage: Turning osTicket PDF Exports into RCE

Comments
2 min read
CVE-2025-61984: Bash a Newline: The SSH ProxyCommand RCE You Didn't Know You Had

CVE-2025-61984: Bash a Newline: The SSH ProxyCommand RCE You Didn't Know You Had

Comments
2 min read
CVE-2026-23498: Shopware 6: Mapping Your Way to RCE via Twig Type Juggling

CVE-2026-23498: Shopware 6: Mapping Your Way to RCE via Twig Type Juggling

Comments
2 min read
Why Risk-Based Code Paths Beat Full Visualization
Cover image for Why Risk-Based Code Paths Beat Full Visualization

Why Risk-Based Code Paths Beat Full Visualization

1
Comments
9 min read
Modeling identity and access hierarchy in Postgres with ltree

Modeling identity and access hierarchy in Postgres with ltree

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.