<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Denial-of-Service — PoC Archive</title><link>https://poc.intelseclab.com/tags/denial-of-service/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 12 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/denial-of-service/index.xml" rel="self" type="application/rss+xml"/><item><title>Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-56260 (GHSA-365w-hqf6-vxfg). Status: PoC — lab (vulnerable-app/) demonstrates genuine unrestricted arbitrary file write; the bundled poc.py scanner is deliberately conservative (writes only to a randomized safe /tmp marker) so it is safe to run against real/production targets. See Notes.. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper (unclecode/crawl4ai), Docker API server mode. Tags: crawl4ai, ai-web-crawler, docker-api, path-traversal, arbitrary-file-write, cwe-22, unauthenticated, remote, denial-of-service.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>ai-web-crawler</category><category>docker-api</category><category>path-traversal</category><category>arbitrary-file-write</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>denial-of-service</category></item><item><title>ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</guid><description>High severity — network · CVE-2026-34473. Status: PoC. Affects: ZTE H-series routers (17+ models, reported as affecting 140K+ devices). Tags: router, firmware, unauthenticated, denial-of-service, iot, zte, cgilua, web-interface.</description><category>network</category><category>High</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>denial-of-service</category><category>iot</category><category>zte</category><category>cgilua</category><category>web-interface</category></item><item><title>Windows CLFS.sys Unrecoverable State / BSoD via ReadFile on Log File Handle (CVE-2026-2636)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2636-clfs-sys-bsod/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2636-clfs-sys-bsod/</guid><description>Medium severity — binary · CVE-2026-2636. Status: PoC. Affects: Windows Common Log File System driver (CLFS.sys, version 10.0.22621.5037 used as reference). Tags: clfs, windows-kernel-driver, bsod, denial-of-service, cwe-159, irp, kebugcheckex, unprivileged.</description><category>binary</category><category>Medium</category><category>clfs</category><category>windows-kernel-driver</category><category>bsod</category><category>denial-of-service</category><category>cwe-159</category><category>irp</category><category>kebugcheckex</category><category>unprivileged</category></item><item><title>TanStack Query — Unbounded Recursion Denial of Service in `replaceEqualDeep` (CVE-2026-26903)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26903-tanstack-query-dos-recursion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26903-tanstack-query-dos-recursion/</guid><description>Medium severity — web · CVE-2026-26903. Status: PoC. Affects: TanStack Query (@tanstack/query-core and framework bindings: react-query, vue-query, solid-query, svelte-query). Tags: tanstack-query, javascript, denial-of-service, stack-overflow, recursion, react, frontend, client-side-dos.</description><category>web</category><category>Medium</category><category>tanstack-query</category><category>javascript</category><category>denial-of-service</category><category>stack-overflow</category><category>recursion</category><category>react</category><category>frontend</category><category>client-side-dos</category></item><item><title>Sliver C2 Server mTLS Nil-Pointer Panic / Infrastructure Kill-Switch — CVE-2026-29781</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-29781-sliver-c2-mtls-panic/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-29781-sliver-c2-mtls-panic/</guid><description>High severity — network · CVE-2026-29781 (GHSA-hx52-cv84-jr5v). Status: PoC. Affects: Sliver C2 server (BishopFox). Tags: sliver-c2, denial-of-service, nil-pointer-dereference, protobuf, mtls, golang, red-team-tooling.</description><category>network</category><category>High</category><category>sliver-c2</category><category>denial-of-service</category><category>nil-pointer-dereference</category><category>protobuf</category><category>mtls</category><category>golang</category><category>red-team-tooling</category></item><item><title>rldns 1.3 Heap-Based Out-of-Bounds Read Remote DoS (CVE-2026-27831)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-27831-rldns-heap-oob-read-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-27831-rldns-heap-oob-read-dos/</guid><description>Medium severity — binary · CVE-2026-27831. Status: PoC. Affects: rldns 1.3 (open-source DNS server). Tags: dns, heap-overflow, out-of-bounds-read, denial-of-service, rldns, memory-corruption, x86_64.</description><category>binary</category><category>Medium</category><category>dns</category><category>heap-overflow</category><category>out-of-bounds-read</category><category>denial-of-service</category><category>rldns</category><category>memory-corruption</category><category>x86_64</category></item><item><title>pypdf Circular Outline Reference Infinite-Loop DoS (CVE-2026-24688)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-24688-pypdf-outline-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-24688-pypdf-outline-dos/</guid><description>High severity — misc · CVE-2026-24688. Status: PoC. Affects: pypdf (Python PDF library). Tags: pypdf, python, denial-of-service, infinite-loop, malicious-pdf, memory-exhaustion, outline-parsing, cwe-835.</description><category>misc</category><category>High</category><category>pypdf</category><category>python</category><category>denial-of-service</category><category>infinite-loop</category><category>malicious-pdf</category><category>memory-exhaustion</category><category>outline-parsing</category><category>cwe-835</category></item><item><title>PX4-Autopilot tattu_can Driver — CAN Bus Stack Buffer Overflow DoS (CVE-2026-32707)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-32707-px4-tattu-can-buffer-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-32707-px4-tattu-can-buffer-overflow/</guid><description>High severity (CVSS 7.5) — hardware · CVE-2026-32707 (GHSA-wxwm-xmx9-hr32, CWE-121). Status: PoC. Affects: PX4-Autopilot flight controller firmware, tattu_can driver. Tags: px4, autopilot, can-bus, socketcan, stack-buffer-overflow, drone, uav, denial-of-service.</description><category>hardware</category><category>High</category><category>px4</category><category>autopilot</category><category>can-bus</category><category>socketcan</category><category>stack-buffer-overflow</category><category>drone</category><category>uav</category><category>denial-of-service</category></item><item><title>PX4 Autopilot MAVLink FTP Stack Buffer Overflow (CVE-2026-32743)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-32743-px4-mavlink-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-32743-px4-mavlink-overflow/</guid><description>Medium severity (CVSS 6.5) — hardware · CVE-2026-32743. Status: PoC. Affects: PX4 Autopilot flight controller firmware. Tags: px4, autopilot, mavlink, drone, uav, buffer-overflow, denial-of-service, mavlink-ftp.</description><category>hardware</category><category>Medium</category><category>px4</category><category>autopilot</category><category>mavlink</category><category>drone</category><category>uav</category><category>buffer-overflow</category><category>denial-of-service</category><category>mavlink-ftp</category></item><item><title>PJSIP DNS Compression Pointer Heap Out-of-Bounds Read (CVE-2026-32945)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-32945-pjsip-dns-oob-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-32945-pjsip-dns-oob-read/</guid><description>Medium severity — network · CVE-2026-32945. Status: PoC. Affects: pjproject (PJSIP library) — used by Asterisk, FreeSWITCH, and other SIP applications. Tags: pjsip, pjproject, dns, heap-oob-read, denial-of-service, asterisk, freeswitch, sip.</description><category>network</category><category>Medium</category><category>pjsip</category><category>pjproject</category><category>dns</category><category>heap-oob-read</category><category>denial-of-service</category><category>asterisk</category><category>freeswitch</category><category>sip</category></item><item><title>Oracle VirtualBox Shared Folders Kernel Memory Exhaustion DoS (CVE-2026-21986)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-21986-virtualbox-shared-folder-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-21986-virtualbox-shared-folder-dos/</guid><description>Medium severity (CVSS 7.1) — binary · CVE-2026-21986. Status: PoC. Affects: Oracle VM VirtualBox — Shared Folders kernel driver (VBoxMiniRdr, Windows guest). Tags: virtualbox, denial-of-service, kernel-memory-exhaustion, ioctl, shared-folders, windows-driver, non-paged-pool.</description><category>binary</category><category>Medium</category><category>virtualbox</category><category>denial-of-service</category><category>kernel-memory-exhaustion</category><category>ioctl</category><category>shared-folders</category><category>windows-driver</category><category>non-paged-pool</category></item><item><title>OpenSTAManager Global Search Amplified Time-Based Blind SQL Injection — CVE-2026-24417</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24417-openstamanager-sqli-search-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24417-openstamanager-sqli-search-dos/</guid><description>High severity — web · CVE-2026-24417. Status: PoC. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: sql-injection, time-based-blind, openstamanager, php, denial-of-service, ajax, authenticated.</description><category>web</category><category>High</category><category>sql-injection</category><category>time-based-blind</category><category>openstamanager</category><category>php</category><category>denial-of-service</category><category>ajax</category><category>authenticated</category></item><item><title>Multiparty Denial of Service via Prototype-Pollution Field Name (CVE-2026-8161)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-8161-multiparty-prototype-pollution-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-8161-multiparty-prototype-pollution-dos/</guid><description>Medium severity — misc · CVE-2026-8161 / GHSA-qxch-whhj-8956. Status: PoC. Affects: multiparty (npm package, multipart/form-data parser). Tags: multiparty, nodejs, prototype-pollution, denial-of-service, cwe-1321, uncaught-exception, multipart-parser.</description><category>misc</category><category>Medium</category><category>multiparty</category><category>nodejs</category><category>prototype-pollution</category><category>denial-of-service</category><category>cwe-1321</category><category>uncaught-exception</category><category>multipart-parser</category></item><item><title>Marlin Firmware M421 G-code Handler Out-of-Bounds Write — CVE-2026-56111</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-56111-marlin-m421-oob-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-56111-marlin-m421-oob-write/</guid><description>High severity (CVSS 8.3) — hardware · CVE-2026-56111. Status: PoC. Affects: Marlin Firmware (3D printer firmware), builds compiled with MESH_BED_LEVELING. Tags: marlin, 3d-printer, firmware, g-code, out-of-bounds-write, mesh-bed-leveling, denial-of-service, embedded.</description><category>hardware</category><category>High</category><category>marlin</category><category>3d-printer</category><category>firmware</category><category>g-code</category><category>out-of-bounds-write</category><category>mesh-bed-leveling</category><category>denial-of-service</category><category>embedded</category></item><item><title>Linux Kernel ICMP Fragmentation-Needed NULL Pointer Dereference (CVE-2026-23398)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23398-icmp-frag-needed/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23398-icmp-frag-needed/</guid><description>High severity — network · CVE-2026-23398. Status: PoC. Affects: Linux kernel, icmp_tag_validation() / icmp_unreach() in net/ipv4/icmp.c. Tags: linux-kernel, icmp, denial-of-service, null-pointer-dereference, kernel-panic, pmtu, scapy, remote-dos.</description><category>network</category><category>High</category><category>linux-kernel</category><category>icmp</category><category>denial-of-service</category><category>null-pointer-dereference</category><category>kernel-panic</category><category>pmtu</category><category>scapy</category><category>remote-dos</category></item><item><title>ChatterBot Denial of Service via SQLAlchemy Connection Pool Exhaustion (CVE-2026-23842)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23842-chatterbot-dos-pool-exhaustion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23842-chatterbot-dos-pool-exhaustion/</guid><description>High severity (CVSS 7.5) — misc · CVE-2026-23842. Status: PoC. Affects: ChatterBot (Python conversational AI library). Tags: chatterbot, denial-of-service, sqlalchemy, connection-pool-exhaustion, python, cwe-400, resource-exhaustion.</description><category>misc</category><category>High</category><category>chatterbot</category><category>denial-of-service</category><category>sqlalchemy</category><category>connection-pool-exhaustion</category><category>python</category><category>cwe-400</category><category>resource-exhaustion</category></item><item><title>BIRD/BIRD2 BGP AS_PATH Mask Matching Stack Buffer Overflow (CVE-2026-49943)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49943-bird-bgp-aspath-stack-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49943-bird-bgp-aspath-stack-overflow/</guid><description>High severity (CVSS 3.1) — network · CVE-2026-49943. Status: PoC. Affects: BIRD Internet Routing Daemon (BGP implementation). Tags: bird, bird2, bgp, as-path, stack-buffer-overflow, denial-of-service, routing, dos.</description><category>network</category><category>High</category><category>bird</category><category>bird2</category><category>bgp</category><category>as-path</category><category>stack-buffer-overflow</category><category>denial-of-service</category><category>routing</category><category>dos</category></item><item><title>Apache HTTP Server HTTP/2 HPACK Cookie-Merging Memory Bomb (CVE-2026-49975)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49975-apache-http2-cookie-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49975-apache-http2-cookie-bomb-dos/</guid><description>High severity — network · CVE-2026-49975. Status: PoC. Affects: Apache HTTP Server (mod_http2). Tags: apache, httpd, http2, hpack, mod_http2, cookie-header, memory-exhaustion, denial-of-service, flow-control.</description><category>network</category><category>High</category><category>apache</category><category>httpd</category><category>http2</category><category>hpack</category><category>mod_http2</category><category>cookie-header</category><category>memory-exhaustion</category><category>denial-of-service</category><category>flow-control</category></item><item><title>Algorithmic Complexity DoS in musl libc `iconv` GB18030 Decoder — CVE-2026-6042</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6042-poc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6042-poc/</guid><description>High severity (CVSS 7.5) — network · CVE-2026-6042. Status: PoC. Affects: musl libc — iconv implementation (GB18030 and EUC-KR decoders). Tags: musl, libc, iconv, denial-of-service, algorithmic-complexity, gb18030, alpine-linux.</description><category>network</category><category>High</category><category>musl</category><category>libc</category><category>iconv</category><category>denial-of-service</category><category>algorithmic-complexity</category><category>gb18030</category><category>alpine-linux</category></item><item><title>Nmap IPv6 Extension-Header Length Wrap</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_nmap-ipv6-extension-length-wrap/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_nmap-ipv6-extension-length-wrap/</guid><description>Low severity — network · None assigned as of 2026-07-03. Status: Incomplete PoC. Affects: Nmap — shared packet parsing code (libnetutil/netutil.cc, tcpip.cc). Tags: nmap, ipv6, integer-wraparound, packet-parsing, libnetutil, extension-headers, denial-of-service, research-in-progress.</description><category>network</category><category>Low</category><category>nmap</category><category>ipv6</category><category>integer-wraparound</category><category>packet-parsing</category><category>libnetutil</category><category>extension-headers</category><category>denial-of-service</category><category>research-in-progress</category></item></channel></rss>