PoC Archive PoC Archive

tag

Tls

  • CVE-2026-40701 web MEDIUM 6.3

    nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)

    nginx's resolver contains a use-after-free that is reachable when a server is configured with sslstapling on;, sslstaplingverify on;, and a resolver directive — the combination that causes nginx to perform DNS resolution of the OCSP responder hostname on the…

    Patched 2026-07-05
  • CVE-2026-8932 network LOW

    libcurl mTLS Connection Reuse Authentication Bypass (CVE-2026-8932)

    CVE-2026-8932 is a Low-severity authentication bypass in libcurl's TLS connection reuse logic. Certain mTLS private-key configuration parameters (key file path, key type, key password) were omitted from the connection-matching comparison performed when…

    Patched 2026-06-30
  • CVE-2025-0282 network CRITICAL 9 KEV Ransomware EPSS 100%

    Ivanti Connect Secure Pre-Auth RCE (Stack Overflow)

    CVE-2025-0282 is a pre-authentication stack-based buffer overflow in the IFT (IF-T) TLS protocol handling code of Ivanti Connect Secure VPN appliances. Discovered and disclosed by Sina Kheirkhah of watchTowr Labs, this zero-day was confirmed by Mandiant as…

    Unverified 2026-05-17
  • CVE-2026-23918 web CRITICAL EPSS 50%

    Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918

    CVE-2026-23918 is a pre-authentication double-free vulnerability in Apache httpd's modhttp2 stream cleanup path. Under affected configurations, a remote attacker can trigger memory corruption over HTTP/2 before authentication. The upstream PoC demonstrates…

    Patched 2026-05-17