<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Http — PoC Archive</title><link>https://poc.intelseclab.com/tags/http/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 03 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/http/index.xml" rel="self" type="application/rss+xml"/><item><title>Nginx HTTP/3 QUIC Pool Corruption RCE (CVE-2026-42530)</title><link>https://poc.intelseclab.com/pocs/binary/2026-09-03_cve-2026-42530-nginx-quic-rce/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-09-03_cve-2026-42530-nginx-quic-rce/</guid><description>High severity (CVSS 8.1) — binary · CVE-2026-42530. Status: PoC. Affects: Nginx (HTTP/3 QUIC module). Tags: RCE, Nginx, HTTP/3, QUIC, pool corruption, heap, Python, remote.</description><category>binary</category><category>High</category><category>RCE</category><category>Nginx</category><category>HTTP/3</category><category>QUIC</category><category>pool corruption</category><category>heap</category><category>Python</category><category>remote</category></item><item><title>Apache HTTP Server mod_auth_digest Timing Attack — CVE-2026-33006</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33006-apache-mod-auth-digest-timing/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33006-apache-mod-auth-digest-timing/</guid><description>Medium severity (CVSS 4.8) — web · CVE-2026-33006. Status: PoC. Affects: Apache HTTP Server (mod_auth_digest module). Tags: apache, mod_auth_digest, timing-attack, authentication-bypass, digest-auth, http, side-channel.</description><category>web</category><category>Medium</category><category>apache</category><category>mod_auth_digest</category><category>timing-attack</category><category>authentication-bypass</category><category>digest-auth</category><category>http</category><category>side-channel</category></item><item><title>Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</guid><description>Critical severity — web · CVE-2026-23918. Status: Weaponized. Affects: Apache HTTP Server (httpd) with mod_http2. Tags: RCE, pre-auth, unauthenticated, double-free, heap-corruption, Apache, httpd, mod_http2, HTTP/2, TLS.</description><category>web</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>double-free</category><category>heap-corruption</category><category>Apache</category><category>httpd</category><category>mod_http2</category><category>HTTP/2</category><category>TLS</category></item></channel></rss>