00Archive

Research notes.

Published write-ups across 0-days, n-days, malware, and anything else that earned a note. Drafts stay off this list until they are cleared.

52 results
000-dayHighPublic

Vaultwarden, default X-Real-IP trusted-local bypasses login rate limits

Vaultwarden 1.37.3 defaults IP_HEADER to X-Real-IP and IP_HEADER_TRUSTED_PROXIES to local. Any non-global TCP peer is treated as a reverse proxy, so a client X-Real-IP becomes the login rate-limit key. Stock Docker published-port NAT is RFC1918. Unique headers never share a burst. 2FA after a correct password still runs. No CVE yet.

02 Oct 2026Vaultwarden
Read analysis→
010-dayHighPublic

Bitwarden, EF cipher create skips collection ACL

Bitwarden Server 2026.9.2 lite on MariaDB/Postgres/SQLite nulls the caller UserId before attaching a new org cipher to collections. A confirmed member can plant a decryptable vault item into a collection they cannot write. Members sync it as a shared login. MSSQL/Dapper keeps the caller id. No CVE yet.

02 Oct 2026Bitwarden
Read analysis→
02N-dayCVE-2026-19445CriticalPublic

CVE-2026-19445: CPython SNI callback frees the server SSLContext

CPython ssl servers that mint an SSLContext per connection, set sni_callback, and assign sslobj.context to a different context can drop the original SSLContext while OpenSSL still holds a borrowed pointer. A second ClientHello (HelloRetryRequest is enough) consults it. Handshake continues. Crash window. Labbed on 3.14.7.

01 Oct 2026Python Software Foundation
Read analysis→
03N-dayCVE-2026-19553HighPublic

CVE-2026-19553: CPython wrap_bio skips hostname verification

CPython ssl.SSLContext.wrap_bio() did not require server_hostname when check_hostname is set. SSLObject silently skips identity checks. The chain verifies. The name does not. wrap_socket already raised. asyncio turns an empty hostname into None and then wrap_bio. Labbed on 3.14.7.

01 Oct 2026Python Software Foundation
Read analysis→
040-dayHighPublic

GitLab, webhook SSRF through 0.0.0.0/8

GitLab 19.4.1 UrlBlocker blocks exact 0.0.0.0 and 127.0.0.0/8, not the rest of 0.0.0.0/8. A Maintainer webhook at http://0.0.0.1/ reaches worker loopback with local-requests off. GitLab stores 8 KB of the body. No CVE yet.

01 Oct 2026GitLab
Read analysis→
060-dayHighPublic

GitLab, Gitea HTTPS import drops the UrlBlocker pin

GitLab 19.4.1 Gitea HTTPS import throws away the IP-pinned URI and reconnects to the original hostname. Rebind that name to loopback and Faraday GETs it. Repo-list JSON comes back on status.json. HTTP imports keep the pin. No CVE yet.

01 Oct 2026GitLab
Read analysis→
070-dayHighPublic

MsQuic, compatible-VN commits Initial keys before AEAD

MsQuic v2.6.1 default client treats a compatible-VN long header as a version switch before AEAD, recreates Initial keys, then either never reverts or restores only the version number. One UDP datagram from the server 4-tuple stops the handshake. No CVE yet.

30 Sept 2026Microsoft
Read analysis→
080-dayCriticalPublic

SONiC gNMI, unauthenticated writes on empty UserAuth

SONiC gNMI still passes --client_auth cert as a fail-closed default, then unsets cert when ca_crt is empty. authenticate() treats empty UserAuth as success. Native and translib writes are compiled in. SmartSwitch DPU with no certs is remote on :8080. Default ToR is loopback. No CVE yet.

30 Sept 2026SONiC
Read analysis→
090-dayHighPublic

n8n, Databricks path join to secrets API

n8n 2.42.0 Databricks Genie getSpace concatenates spaceId with no toPathSegment. Untrusted webhook input becomes GET /api/2.0/secrets/get under the workspace token. Sibling of GHSA-89p4 / GHSA-rqch. No CVE yet.

29 Sept 2026n8n
Read analysis→
100-dayHighPublic

n8n, hidden Function node in-process vm2

n8n 2.42.0 Function / FunctionItem / LangChain Code still run JS via leftover vm2 NodeVM in the main process. Palette hidden is not an ACL. Code v2 already uses the task-runner child. No CVE yet.

29 Sept 2026n8n
Read analysis→
110-dayHighPublic

Uptime Kuma, unauthenticated setup TOCTOU

Uptime Kuma 2.5.5 Socket.IO setup on first-run COUNTs users, bcrypts, then INSERTs. Username is UNIQUE only. Concurrent unauth clients can insert a hidden second admin, then disableAuth auto-logins as user id 1. No CVE yet.

29 Sept 2026Uptime Kuma
Read analysis→
120-dayMediumPublic

Gitea, restore-repo file:// os.Open

Gitea 1.27.3 OpenWithClient still implements file:// with os.Open. Operator restore of an untrusted dump rewrites release DownloadURL to file:// under the dump. os.Open follows a dump symlink. Not live-migrate LFI. No CVE yet.

29 Sept 2026Gitea
Read analysis→
130-dayMediumPublic

Gitea, artifact v4 unbounded ReadAll

Gitea 1.27.3 artifact v4 parseProtobufBody does io.ReadAll with no cap. Job-summary on the same instance already LimitReaders at 1 MiB. A running Actions job token can POST a 12 MiB CreateArtifact. Not process-kill. No CVE yet.

29 Sept 2026Gitea
Read analysis→
140-dayMediumPublic

Gitea, follow existence oracle

Gitea 1.27.3 PUT /api/v1/user/following/{username} skips IsUserVisibleToViewer. Follow of a hidden user is 204. Unknown names 404. GET /users/{name} already 404s hidden users. Status-class oracle only. No CVE yet.

29 Sept 2026Gitea
Read analysis→
160-dayMediumPublic

Gitea, public-only PAT creates private org

Gitea 1.27.3 POST /api/v1/orgs has no rejectPublicOnly. A public-only PAT with write:organization creates a private organization. The same token cannot create a private user repository. No CVE yet.

29 Sept 2026Gitea
Read analysis→
210-dayCriticalPublic

Lago acceptInvite, cross-org account takeover

Lago v1.53.0 acceptInvite has no login. register_from_invite loads the user by invite email. If that account already has memberships, the posted password is ignored and a user-scoped JWT is issued. Inviter already has the token. No CVE yet.

26 Sept 2026Lago
Read analysis→
240-dayHighPublic

Magento Instant Purchase custom_price, authenticated underpay

Magento 2.4.8-p5 Instant Purchase copies every POST field into the buyRequest because $knownRequestParams is a list and isset() looks for keys. Checkout RequestInfoFilter strips custom_price. Instant Purchase does not. Quote Processor setCustomPrice. Lab charged 0.01 against catalog 99.99. No CVE yet.

26 Sept 2026Adobe
Read analysis→
25NotesInfoPublic

Just Blast 0day

The bounty queue is a sewer of AI-generated reports. I have stopped filing the bugs that matter. I write the analysis, release a public PoC, and post the link the same day. If you are holding one, do the same thing.

26 Sept 2026n/a (disclosure policy)
Read analysis→
27N-dayCVE-2026-61628HighPublic

CVE-2026-61628: nginx-ignition, unauthenticated RCE

nginx-ignition 2.41.0 registers POST /api/users/onboarding/finish as anonymous. The handler checks OnboardingCompleted, then Save()s a user with Users=READ_WRITE and returns a JWT. No lock. A virgin instance, or a race that mints two admins. Patched in 2.41.1.

22 Sept 2026lucasdillmann
Read analysis→
28MalwareHighPublic

Two open PRs, one wallet, DPRK PolinRider in shadcn/ui

Two still-open PRs against shadcn-ui/ui carry the same NullReceiver loader OSM tracks as PolinRider. Same Ethereum wallet, live C2 in a zero-value transfer. One PR also drops Fake Font on folderOpen. Static only. I did not run the implant or talk to the C2.

20 Sept 2026n/a (PolinRider / NullReceiver cluster)
Read analysis→
290-dayHighPublic

phpMyAdmin 5.2.3 WebAuthn 2FA, privileged RCE

phpMyAdmin 5.2.3 CustomServer never verifies the WebAuthn assertion signature. After the MySQL password, a forged webauthn_request_response that matches challenge, origin, rpIdHash, and user-present is enough. Default tarball. No CVE yet.

20 Sept 2026phpMyAdmin
Read analysis→
30N-dayCVE-2026-77635CriticalPublic

CVE-2026-77635: CakePHP, unauthenticated RCE

CakePHP FunctionsBuilder::jsonValue on PostgresDriver interpolates $jsonPath into JSONB_PATH_QUERY. quoteIdentifier is not a bind. The lab passes GET path into jsonValue. Not WordPress. Fixed in 5.2.15.

19 Sept 2026CakePHP
Read analysis→
31N-dayCVE-2026-79752CriticalPublic

CVE-2026-79752: CakePHP, unauthenticated RCE

CakePHP FunctionsBuilder::cast splices $dataType into SQL as a literal. extract, datePart, and dateAdd do the same for $part and $unit. The lab passes GET type into cast. Not WordPress. Fixed in 5.2.14 and siblings.

19 Sept 2026CakePHP
Read analysis→
37N-dayCVE-2026-18937CriticalPublic

CVE-2026-18937: Broken Link Checker, unauthenticated RCE

Broken Link Checker 2.4.11 merges every GET key into $wp->query_vars on plain permalinks. WP::register_globals copies those keys into $GLOBALS. Overwrite $shortcode_tags, render a shortcode, call_user_func. Classic theme. Unauthenticated.

19 Sept 2026WPMU DEV
Read analysis→
38N-dayCVE-2026-45140CriticalPublic

CVE-2026-45140: Chamilo LMS, unauthenticated RCE

Chamilo 2.0.0 CStudio big-upload.php takes GET key with no sanitization and no login. fopen appends php://input onto cacheDir plus that key. Traversal into public/ is a web file. The GHSA did not name the path.

18 Sept 2026chamilo
Read analysis→
39N-dayCVE-2026-75827HighPublic

CVE-2026-75827: Grav, privileged RCE

Grav before 2.0.15 allowlists Class::method dynamic-data providers and denylists bare functions. error_log is not on the denylist. A form data-options@ directive appends attacker bytes to a web path. Page-edit.

18 Sept 2026getgrav
Read analysis→
40N-dayCVE-2026-82226CriticalPublic

CVE-2026-82226: Tickera, unauthenticated RCE

Tickera 3.6.0.2 maybe_unserialize()s attendee owner_data *_post_meta in create_order. Cart nonce, cookie, free ticket, then process-payment. Objects run. Unauthenticated. Patched in 3.6.0.3.

18 Sept 2026Tickera
Read analysis→
41N-dayCVE-2026-84753CriticalPublic

CVE-2026-84753: Mail Mint, unauthenticated RCE

Mail Mint 1.31.0 stores extra form fields as contact meta, then maybe_unserialize()s them. Objects run before the is_array discard. The function is named safe_unserialize_meta. Unauthenticated. Two POSTs.

18 Sept 2026WPFunnels
Read analysis→
42N-dayCVE-2026-77991CriticalPublic

CVE-2026-77991: Joomla Event Manager, privileged RCE

JEM 5.0.0's CSS manager writes whatever filename the administrator hands it. resolveSourceFile blocks .. and cleans the path. It does not require .css. A PHP file under media/com_jem/css is the bug. Unauthenticated POST is not.

18 Sept 2026joomlaeventmanager.net
Read analysis→
43N-dayCVE-2026-12793CriticalPublic

CVE-2026-12793: JetFormBuilder, unauthenticated RCE

JetFormBuilder 3.6.2 accepts any post id as a form. parse_blocks on a regular post plus a Register User action is an administrator. The default submit hook is not the router. A 200 with a WordPress theme is not the bug.

18 Sept 2026Crocoblock
Read analysis→
45NotesCVE-2021-41773InfoPublic

M5 Air cybersecurity model tests

32 GB unified memory is enough for an abliterated Qwen that will read a lab CVE, name the sink, and write a PoC. The catch is which Qwen. A 35B MoE OffSec fine-tune runs at 16.6 tok/s on this Air. Dense 27B writes a prettier script and takes eleven minutes to do it.

12 Sept 2026n/a (local llama.cpp eval)
Read analysis→
46Series0-dayHighPublic

Veneficus Mini

Spicy malware. Full kill-chain implant: exploit, escalate, pivot, poison, C2. Windows 10/11 x64 source on GitHub, released as-is and slightly broken on purpose.

04 Sept 2026n/a (private implant kit, source released)
Read series→
47SeriesN-dayCVE-2024-21762CriticalPublic

The SSL-VPN pot of gold

I found a private FortiGate SSL-VPN kit in the wild and released it. 179 working clients, two public CVEs, 53 SKUs. The tree is on GitHub.

31 Aug 2026Fortinet
Read series→
48Series0-dayHighPublic

Hunting the Fortinet Hunter 0-Day

YogSotho hid a Fortinet 0-day hunter behind two locks and a TESO homage. I opened the GoFile share with OSINT plus the listing API, then re-keyed a local copy of the ELF gate without recovering his passphrase. This is the map.

29 Aug 2026Fortinet
Read series→
49MalwareCVE-2019-5736InfoPublic

The binary that wasn’t there

Linux will run a program that has no name. I went looking for folklore and found memfd_create: anonymous RAM, an ELF, and an exe symlink that has been willing to testify the entire time. Stock Debian still leaves the door open.

20 Aug 2026Linux kernel / Debian
Read analysis→
50MalwareHighPublic

beacon.exe: custom Go C2 found in the wild

Found beacon.exe in the wild. The filename begged for Sliver. The pclntab and the C2 URLs said otherwise: a privately built Go implant with HTTPS plus framed TCP, AES-256-GCM, and a full post-ex menu. Not Sliver. Not Cobalt. Not stock Adaptix.

19 Aug 2026n/a (private C2; callback on PEG TECH / AROSSCLOUD)
Read analysis→
51N-dayInfoPublic

Can a Rubber Ducky do Plug & Pwn?

I opened plugandpwn.com with a Rubber Ducky on the desk. The mapping took ten minutes. Different USB device. Different primitive. Different trust boundary. Here is the teaching cut.

18 Aug 2026n/a (HID vs Windows PnP)
Read analysis→