DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2025-69224: Absolute Zero Security: Smuggling Requests into aiohttp with the Kelvin Sign

CVE-2025-69224: Absolute Zero Security: Smuggling Requests into aiohttp with the Kelvin Sign

Comments
2 min read
CVE-2017-5638: The Billion Dollar Header: Inside the Apache Struts 2 'Equifax' RCE

CVE-2017-5638: The Billion Dollar Header: Inside the Apache Struts 2 'Equifax' RCE

Comments
2 min read
CVE-2025-69226: AIOHTTP Side-Channel: When 403 Means 'I See You'

CVE-2025-69226: AIOHTTP Side-Channel: When 403 Means 'I See You'

Comments
2 min read
CVE-2025-69223: Puff, The Magic Dragon: Exploding RAM with aiohttp Zip Bombs

CVE-2025-69223: Puff, The Magic Dragon: Exploding RAM with aiohttp Zip Bombs

Comments
2 min read
CVE-2025-65091: Calendar of Doom: A Critical HQL Injection in XWiki

CVE-2025-65091: Calendar of Doom: A Critical HQL Injection in XWiki

Comments
2 min read
CVE-2026-22798: Loose Lips Sink Ships: How Hermes Logged Its Way into a Security Nightmare

CVE-2026-22798: Loose Lips Sink Ships: How Hermes Logged Its Way into a Security Nightmare

Comments
2 min read
GHSA-MQQF-5WVP-8FH8: Slashing Through the Safety Nets: The go-chi Open Redirect

GHSA-MQQF-5WVP-8FH8: Slashing Through the Safety Nets: The go-chi Open Redirect

Comments
2 min read
CVE-2026-0859: CamelCase Catastrophe: How a Typo in TYPO3 Enabled RCE

CVE-2026-0859: CamelCase Catastrophe: How a Typo in TYPO3 Enabled RCE

Comments
2 min read
CVE-2026-23643: Let Them Eat XSS: Breaking CakePHP's PaginatorHelper

CVE-2026-23643: Let Them Eat XSS: Breaking CakePHP's PaginatorHelper

Comments
2 min read
GHSA-H3HW-29FV-2X75: Context Bleeding: When GraphQL Requests Swap Identities in Envelop

GHSA-H3HW-29FV-2X75: Context Bleeding: When GraphQL Requests Swap Identities in Envelop

Comments
2 min read
CVE-2026-23991: Panic at the Distro: Crashing go-tuf with Malformed JSON

CVE-2026-23991: Panic at the Distro: Crashing go-tuf with Malformed JSON

Comments
2 min read
CVE-2026-23946: Pickle Rick-rolled Again: The Zombie RCE in Tendenci CMS

CVE-2026-23946: Pickle Rick-rolled Again: The Zombie RCE in Tendenci CMS

Comments
2 min read
I Built a Postgres Proxy That Masks PII for AI Agents

I Built a Postgres Proxy That Masks PII for AI Agents

Comments
1 min read
CVE-2025-69229: Death by a Thousand Chunks: The aiohttp O(N^2) DoS

CVE-2025-69229: Death by a Thousand Chunks: The aiohttp O(N^2) DoS

Comments
2 min read
CVE-2026-22036: Death by a Thousand Gzips: The Node.js Undici Decompression Loop

CVE-2026-22036: Death by a Thousand Gzips: The Node.js Undici Decompression Loop

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.