<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Websocket — PoC Archive</title><link>https://poc.intelseclab.com/tags/websocket/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/websocket/index.xml" rel="self" type="application/rss+xml"/><item><title>WebSocket Authentication Brute-Force via Missing Rate Limiting (CVE-2026-27778)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27778-websocket-auth-bruteforce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27778-websocket-auth-bruteforce/</guid><description>Medium severity — web · CVE-2026-27778. Status: PoC. Affects: Generic Node.js/Express + ws WebSocket authentication server (demonstration/simulator app). Tags: websocket, brute-force, cwe-307, rate-limiting, authentication, nodejs, simulator.</description><category>web</category><category>Medium</category><category>websocket</category><category>brute-force</category><category>cwe-307</category><category>rate-limiting</category><category>authentication</category><category>nodejs</category><category>simulator</category></item><item><title>Red Hat Cockpit `logsJournal.jsx` Shell Injection RCE (CVE-2026-4802)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4802-cockpit-logsjournal-shell-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4802-cockpit-logsjournal-shell-injection/</guid><description>High severity — web · CVE-2026-4802. Status: PoC. Affects: Red Hat Cockpit — the web-based Linux system administration console (cockpit-project.org), specifically pkg/systemd/logsJournal.jsx. **Not** to be confused with the headless "Cockpit CMS".. Tags: cockpit, redhat, shell-injection, command-injection, rce, websocket, systemd, journalctl.</description><category>web</category><category>High</category><category>cockpit</category><category>redhat</category><category>shell-injection</category><category>command-injection</category><category>rce</category><category>websocket</category><category>systemd</category><category>journalctl</category></item><item><title>OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-28466-openclaw-gateway-websocket-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-28466-openclaw-gateway-websocket-rce/</guid><description>Critical severity — network · CVE-2026-28466. Status: Weaponized. Affects: OpenClaw gateway. Tags: openclaw, websocket, rce, gateway, auth-bypass, node-invoke, command-injection.</description><category>network</category><category>Critical</category><category>openclaw</category><category>websocket</category><category>rce</category><category>gateway</category><category>auth-bypass</category><category>node-invoke</category><category>command-injection</category></item><item><title>GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5173-gitlab-websocket-graphql-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5173-gitlab-websocket-graphql-bypass/</guid><description>High severity — web · CVE-2026-5173. Status: PoC. Affects: GitLab CE/EE, ActionCable WebSocket endpoint (/-/cable), GraphqlChannel. Tags: gitlab, websocket, graphql, actioncable, graphqlchannel, information-disclosure, broken-access-control.</description><category>web</category><category>High</category><category>gitlab</category><category>websocket</category><category>graphql</category><category>actioncable</category><category>graphqlchannel</category><category>information-disclosure</category><category>broken-access-control</category></item><item><title>Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-websocket-upgrade-ssrf-self-hosted/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-websocket-upgrade-ssrf-self-hosted/</guid><description>High severity (CVSS 8.6) — web · CVE-2026-44578. Status: Weaponized. Affects: Next.js standalone router server (next start). Tags: SSRF, WebSocket, upgrade-request, Next.js, self-hosted, unauthenticated, metadata-service.</description><category>web</category><category>High</category><category>SSRF</category><category>WebSocket</category><category>upgrade-request</category><category>Next.js</category><category>self-hosted</category><category>unauthenticated</category><category>metadata-service</category></item><item><title>Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-fortiproxy-auth-bypass-cve-2024-55591/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-fortiproxy-auth-bypass-cve-2024-55591/</guid><description>Critical severity (CVSS 9.6) — web · CVE-2024-55591 (Fortinet FG-IR-24-535). Status: Weaponized — public PoC exploit code available, listed in CISA KEV (added 2025-01-14), confirmed used in ransomware intrusions. Affects: Fortinet FortiOS/FortiProxy management interfaces. Tags: auth-bypass, websocket, race-condition, FortiOS, FortiProxy, unauthenticated, super-admin, kev, known-ransomware-use, cwe-288.</description><category>web</category><category>Critical</category><category>auth-bypass</category><category>websocket</category><category>race-condition</category><category>FortiOS</category><category>FortiProxy</category><category>unauthenticated</category><category>super-admin</category><category>kev</category><category>known-ransomware-use</category><category>cwe-288</category></item></channel></rss>