PoC Archive PoC Archive

tag

Middleware

  • CVE-2025-54123 web CRITICAL 9.8 EPSS 11%

    Hoverfly Middleware Command Injection to RCE (CVE-2025-54123)

    Hoverfly exposes a middleware configuration API (/api/v2/hoverfly/middleware) that lets an authenticated admin register an external "middleware" process to pre/post-process simulated HTTP traffic, specified as a binary (interpreter/executable) plus a script…

    Patched 2026-07-06
  • None assigned as of 2026-07-03 web HIGH

    Discourse Scoped API Key Pre-Route Authorization Bypass

    Discourse's overload-protection middleware authenticates API requests before Rails routing has resolved the actual HTTP verb, and its scoped API key matcher (lib/routematcher.rb) calls Rails.application.routes.recognizepath(request.pathinfo) without passing…

    Unverified 2026-07-03