research
Published vulnerabilities and writeups. Newest first.
- cve · 2026-08-14 · vm2 · Critical · cvss 9.8
CVE-2026-47698: vm2 Sandbox Breakout via Host Prototype Mutators
A stacked-indirection bypass in vm2's sandbox bridge exposed dangerous host prototype mutators, allowing sandboxed JavaScript to escape and execute arbitrary commands on the host. Affects vm2 through 3.11.5; fixed in 3.11.6.
- writeup · 2026-04-26
Wonder Ad Blocker: Reverse Engineering a Malicious Chrome Extension
A Chrome extension marketed as an ad blocker — with 500,000+ users — was operating as a distributed ad-intelligence scraping platform. Reverse engineering revealed tracking-script injection, browsing-data harvesting, and command infrastructure phone-home.
- writeup · 2026-04-06
48 Hours on a SCADA Honeypot
A SCADA-themed honeypot on Hetzner caught WannaCry samples still propagating in 2026, Outlaw/mdrfckr botnet credential stuffing, Solana validator credential harvesting, and automated Modbus/TCP scanning.
- cve · 2026-04-02 · Envoy · Medium · cvss 6.3
CVE-2026-6994: Envoy Query Parameter Injection via header_mutation
Envoy's header_mutation filter inserts header values into query strings without URL encoding, enabling arbitrary query-parameter injection — auth bypass, SQLi/XSS on upstream services. Affects v1.33.0+.
- cve · 2026-03-18 · Traefik · High · cvss 8.2
CVE-2026-31360: Traefik SPIFFE Trust Domain Bypass
Traefik SPIFFE trust-domain bypass: cert host overwrote the expected host before comparison, enabling cross-trust-domain service impersonation.
- cve · 2026-03-18 · Traefik · Medium
CVE-2026-31361: Traefik ACME Private Key Exposure via Logs
Traefik ACME private-key exposure: %+v logged the full DER-encoded key on parse failure — a five-year unported regression of a partial v1.7.20 fix.
- cve · 2026-03-04 · etcd · Medium · cvss 6.5
CVE-2026-33343: etcd Nested Transactions Bypass RBAC
An authenticated user with restricted key-range permissions can use nested transactions to access the entire etcd data store, bypassing RBAC entirely.
- cve · 2026-03-04 · etcd · High · cvss 8.8
CVE-2026-33413: etcd Authorization Bypass Across Multiple APIs
Multiple etcd APIs reachable without authorization: MemberList (cluster topology), Alarm, Lease APIs, and compaction. CVSS 8.8.