<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Docker-Lab — PoC Archive</title><link>https://poc.intelseclab.com/tags/docker-lab/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/docker-lab/index.xml" rel="self" type="application/rss+xml"/><item><title>Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22738-spring-ai-spel-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22738-spring-ai-spel-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-22738. Status: Weaponized. Affects: Spring AI spring-ai-core (SimpleVectorStore). Tags: spring-ai, spel-injection, java, rce, vector-store, unauthenticated, cwe-94, docker-lab.</description><category>web</category><category>Critical</category><category>spring-ai</category><category>spel-injection</category><category>java</category><category>rce</category><category>vector-store</category><category>unauthenticated</category><category>cwe-94</category><category>docker-lab</category></item><item><title>Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32604-spinnaker-git-clone-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32604-spinnaker-git-clone-rce/</guid><description>Critical severity (CVSS 10) — cloud · CVE-2026-32604 (CWE-78). Status: PoC. Affects: Spinnaker (Clouddriver service) — continuous delivery / multi-cloud orchestration platform. Tags: spinnaker, clouddriver, command-injection, rce, cd-pipeline, cloud-credentials, shell-injection, docker-lab.</description><category>cloud</category><category>Critical</category><category>spinnaker</category><category>clouddriver</category><category>command-injection</category><category>rce</category><category>cd-pipeline</category><category>cloud-credentials</category><category>shell-injection</category><category>docker-lab</category></item><item><title>rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41179-rclone-rc-api-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41179-rclone-rc-api-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-41179. Status: Weaponized. Affects: rclone (Remote Control / rcd HTTP API). Tags: rclone, rce, unauthenticated, webdav, rc-api, command-injection, docker-lab.</description><category>web</category><category>Critical</category><category>rclone</category><category>rce</category><category>unauthenticated</category><category>webdav</category><category>rc-api</category><category>command-injection</category><category>docker-lab</category></item><item><title>OWASP CoreRuleSet Multipart Charset WAF Bypass (CVE-2026-21876)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21876-crs-waf-multipart-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21876-crs-waf-multipart-bypass/</guid><description>Critical severity — web · CVE-2026-21876. Status: PoC. Tags: waf-bypass, owasp-crs, modsecurity, multipart-form-data, charset-smuggling, xss, docker-lab.</description><category>web</category><category>Critical</category><category>waf-bypass</category><category>owasp-crs</category><category>modsecurity</category><category>multipart-form-data</category><category>charset-smuggling</category><category>xss</category><category>docker-lab</category></item><item><title>nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40701-nginx-resolver-ocsp-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40701-nginx-resolver-ocsp-uaf/</guid><description>Medium severity (CVSS 6.3) — web · CVE-2026-40701. Status: PoC. Affects: nginx (open source). Tags: nginx, use-after-free, ocsp-stapling, resolver, memory-corruption, docker-lab, tls.</description><category>web</category><category>Medium</category><category>nginx</category><category>use-after-free</category><category>ocsp-stapling</category><category>resolver</category><category>memory-corruption</category><category>docker-lab</category><category>tls</category></item><item><title>NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42926-nginx-http2-frame-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42926-nginx-http2-frame-injection/</guid><description>High severity — web · CVE-2026-42926. Status: PoC. Affects: NGINX (HTTP/2 upstream proxying). Tags: nginx, http2, frame-injection, reverse-proxy, request-smuggling, docker-lab.</description><category>web</category><category>High</category><category>nginx</category><category>http2</category><category>frame-injection</category><category>reverse-proxy</category><category>request-smuggling</category><category>docker-lab</category></item><item><title>MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-32710-mariadb-json-schema-udf-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-32710-mariadb-json-schema-udf-rce/</guid><description>Critical severity — binary · CVE-2026-32710. Status: PoC. Affects: MariaDB (JSON_SCHEMA_VALID() SQL function). Tags: mariadb, mysql, heap-overflow, privilege-escalation, udf, raptor-udf, sql, json, docker-lab.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>mysql</category><category>heap-overflow</category><category>privilege-escalation</category><category>udf</category><category>raptor-udf</category><category>sql</category><category>json</category><category>docker-lab</category></item><item><title>Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42048-langflow-kb-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42048-langflow-kb-path-traversal/</guid><description>High severity — web · CVE-2026-42048 (GHSA-9whx-c884-c68q). Status: PoC. Affects: Langflow (Knowledge Bases bulk delete API). Tags: langflow, path-traversal, arbitrary-file-deletion, cwe-22, api, docker-lab, knowledge-base.</description><category>web</category><category>High</category><category>langflow</category><category>path-traversal</category><category>arbitrary-file-deletion</category><category>cwe-22</category><category>api</category><category>docker-lab</category><category>knowledge-base</category></item><item><title>Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-53435-jenkins-deser-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-53435-jenkins-deser-file-read/</guid><description>High severity (CVSS 9.1) — web · CVE-2026-53435 (Jenkins SECURITY-3707). Status: PoC. Affects: Jenkins (core), View configuration (config.xml) deserialization path. Tags: jenkins, deserialization, classfilter-bypass, xstream, config-xml, stapler, arbitrary-file-read, docker-lab, cwe-502.</description><category>web</category><category>High</category><category>jenkins</category><category>deserialization</category><category>classfilter-bypass</category><category>xstream</category><category>config-xml</category><category>stapler</category><category>arbitrary-file-read</category><category>docker-lab</category><category>cwe-502</category></item><item><title>Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion (CVE-2026-1281 / CVE-2026-1340)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1281-ivanti-epmm-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1281-ivanti-epmm-rce/</guid><description>Critical severity — network · CVE-2026-1281, CVE-2026-1340. Status: PoC. Affects: Ivanti Endpoint Manager Mobile (EPMM), map-appstore-url CGI handler. Tags: ivanti, epmm, mobileiron, pre-auth-rce, bash, arithmetic-expansion, command-injection, docker-lab.</description><category>network</category><category>Critical</category><category>ivanti</category><category>epmm</category><category>mobileiron</category><category>pre-auth-rce</category><category>bash</category><category>arithmetic-expansion</category><category>command-injection</category><category>docker-lab</category></item><item><title>Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42589-gotenberg-exiftool-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42589-gotenberg-exiftool-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42589. Status: PoC. Affects: Gotenberg (document/PDF conversion microservice). Tags: gotenberg, exiftool, command-injection, cwe-78, unauthenticated, rce, docker-lab, nuclei.</description><category>web</category><category>Critical</category><category>gotenberg</category><category>exiftool</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>rce</category><category>docker-lab</category><category>nuclei</category></item><item><title>Claude Code WebFetch Hardcoded HuggingFace Bare-Hostname Allow-List Bypass — CVE-2026-54316</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-54316-claude-code-webfetch-hf-exfil/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-54316-claude-code-webfetch-hf-exfil/</guid><description>Medium severity — misc · CVE-2026-54316 (GHSA-fg94-h982-f3mm). Status: PoC. Affects: @anthropic-ai/claude-code (npm package, Claude Code CLI). Tags: claude-code, webfetch, prompt-injection, exfiltration, huggingface, allow-list-bypass, agentic-ai, docker-lab, cwe-183.</description><category>misc</category><category>Medium</category><category>claude-code</category><category>webfetch</category><category>prompt-injection</category><category>exfiltration</category><category>huggingface</category><category>allow-list-bypass</category><category>agentic-ai</category><category>docker-lab</category><category>cwe-183</category></item><item><title>Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2576-business-directory-plugin-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2576-business-directory-plugin-sqli/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-2576. Status: Weaponized. Affects: Business Directory Plugin (Easy Listing Directories) for WordPress. Tags: wordpress, sqli, time-based-blind, business-directory-plugin, unauthenticated, cwe-89, wpdb, docker-lab.</description><category>web</category><category>High</category><category>wordpress</category><category>sqli</category><category>time-based-blind</category><category>business-directory-plugin</category><category>unauthenticated</category><category>cwe-89</category><category>wpdb</category><category>docker-lab</category></item><item><title>Apache Tomcat Mutual TLS OCSP Soft-Fail Authentication Bypass — CVE-2026-29145</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29145-tomcat-mtls-ocsp-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29145-tomcat-mtls-ocsp-bypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-29145. Status: PoC. Affects: Apache Tomcat (CLIENT_CERT / Mutual TLS authentication). Tags: tomcat, mtls, client-cert, ocsp, auth-bypass, revocation-check, docker-lab, java.</description><category>web</category><category>Critical</category><category>tomcat</category><category>mtls</category><category>client-cert</category><category>ocsp</category><category>auth-bypass</category><category>revocation-check</category><category>docker-lab</category><category>java</category></item></channel></rss>