PoC Archive PoC Archive

tag

Reverse-Proxy

Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
CVE-2026-20896 (GHSA-f75j-4cw6-rmx4) web Patched
CVE-2026-20896webCRITICAL 9.8Patched2026-07-11NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)
CVE-2026-42926 web Patched
CVE-2026-42926webHIGHPatched2026-07-05HAProxy HTTP/3 (QUIC) Standalone FIN Body Validation Bypass Leading to Request Smuggling — CVE-2026-33555
CVE-2026-33555 network Patched
CVE-2026-33555networkHIGHPatched2026-07-05Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908
CVE-2026-31908 web Patched
CVE-2026-31908webCRITICAL 10Patched2026-07-05nghttpx HTTP/1.1 Upgrade Request Body Response Queue Poisoning
None assigned as of 2026-07-03 network Patched
None assigned as of 2026-07-03networkHIGHPatched2026-07-03