<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>winfunc</title>
    <link>https://winfunc.com</link>
    <description>AI-native security engineering platform. Find, triage, and patch security vulnerabilities in hours.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 20 Jul 2026 04:41:56 GMT</lastBuildDate>
    <atom:link href="https://winfunc.com/feed.xml" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://winfunc.com/winfunc-text-icon-white.png</url>
      <title>winfunc</title>
      <link>https://winfunc.com</link>
    </image>
    
    <item>
      <title><![CDATA[Hacking the old HackerNews codebase]]></title>
      <link>https://winfunc.com/research/hacking-the-old-hackernews-codebase</link>
      <guid isPermaLink="true">https://winfunc.com/research/hacking-the-old-hackernews-codebase</guid>
      <pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate>
      <author>Mufeed VH</author>
      <description><![CDATA[Auditing the old HackerNews codebase for security vulnerabilities with LLMs on a specialized harness.]]></description>
      <category>Research</category>
      <category>research</category>
      <category>fun</category>
    </item>
    <item>
      <title><![CDATA[What an automated vulnerability research system actually found]]></title>
      <link>https://winfunc.com/research/what-an-automated-vulnerability-research-system-actually-found</link>
      <guid isPermaLink="true">https://winfunc.com/research/what-an-automated-vulnerability-research-system-actually-found</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
      <author>Mufeed VH</author>
      <description><![CDATA[Thirteen patched bugs across nine projects, including Node.js, React, NGINX, Mattermost, Supabase, Bun, Gumroad, Anthropic&apos;s MCP SDK, and Better-Auth. What the system got right, where it still falls over, and why executable PoCs matter more than model reasoning.]]></description>
      <category>Research</category>
      <category>research</category>
      <category>hacktivity</category>
      <category>security</category>
    </item>
    <item>
      <title><![CDATA[How Asterisk Works]]></title>
      <link>https://winfunc.com/research/how-winfunc-works</link>
      <guid isPermaLink="true">https://winfunc.com/research/how-winfunc-works</guid>
      <pubDate>Fri, 30 Aug 2024 00:00:00 GMT</pubDate>
      <author>Mufeed VH</author>
      <description><![CDATA[A repost of the original Asterisk architecture: how an AI security agent indexed code, generated attack ideas, verified vulnerabilities, and produced patches with low-noise reports.]]></description>
      <category>Research</category>
      <category>engineering</category>
      <category>repost</category>
      <category>deprecated</category>
    </item>
    
    <item>
      <title><![CDATA[How Do I Enhance Cloud Security With AI? A Practical Overview]]></title>
      <link>https://winfunc.com/blog/enhance-cloud-security-with-ai</link>
      <guid isPermaLink="true">https://winfunc.com/blog/enhance-cloud-security-with-ai</guid>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Team</author>
      <description><![CDATA[How do I enhance cloud security with AI? Learn where AI improves cloud security, where it creates risk, and how to build a practical AI cloud security roadmap.]]></description>
      <category>Blog</category>
      <category>cloud security AI</category>
      <category>AI cloud security</category>
      <category>cloud threat detection</category>
    </item>
    <item>
      <title><![CDATA[AI SAST With Low False Positives: What Actually Works]]></title>
      <link>https://winfunc.com/blog/ai-sast-low-false-positives</link>
      <guid isPermaLink="true">https://winfunc.com/blog/ai-sast-low-false-positives</guid>
      <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Team</author>
      <description><![CDATA[AI SAST with low false positives depends on reachability, code context, memory, and validation. Learn what works, what fails, and how AppSec teams should evaluate AI-powered SAST.]]></description>
      <category>Blog</category>
      <category>AI SAST</category>
      <category>SAST false positives</category>
      <category>application security testing</category>
    </item>
    <item>
      <title><![CDATA[SAST vs DAST: What&apos;s the Difference and When Should You Use Each?]]></title>
      <link>https://winfunc.com/blog/sast-vs-dast</link>
      <guid isPermaLink="true">https://winfunc.com/blog/sast-vs-dast</guid>
      <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Team</author>
      <description><![CDATA[SAST vs DAST explained: compare static and dynamic application security testing, see examples, pros and cons, CI/CD guidance, and a 2026 AppSec workflow.]]></description>
      <category>Blog</category>
      <category>SAST vs DAST</category>
      <category>application security testing</category>
      <category>DevSecOps</category>
    </item>
    <item>
      <title><![CDATA[AI Vulnerability Triage: A Practical Guide for AppSec Teams]]></title>
      <link>https://winfunc.com/blog/ai-vulnerability-triage</link>
      <guid isPermaLink="true">https://winfunc.com/blog/ai-vulnerability-triage</guid>
      <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Team</author>
      <description><![CDATA[AI vulnerability triage helps AppSec teams validate findings, prove exploitability, prioritize risk, and route fixes. Learn what it can automate, where it fails, and how to evaluate it.]]></description>
      <category>Blog</category>
      <category>AI vulnerability triage</category>
      <category>vulnerability triage</category>
      <category>application security</category>
      <category>code security</category>
      <category>DevSecOps</category>
      <category>vulnerability management</category>
    </item>
    
    <item>
      <title><![CDATA[Stream complex-value capture desynchronization causes heap overflow (CVE-2026-42533)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-42533</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-42533</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[`ngx_stream_complex_value()` calculated an output length and copied the output in separate passes over mutable session-wide regex capture state. In a stream expression such as `return &quot;$1$m&quot;`, the first pass initially counted `$1` as zero bytes. Evaluating the later `$m` variable ran a regex-backed `map` over attacker-controlled TLS SNI and populated the session&apos;s capture array. The copy pass then revisited `$1`, found the new capture, and copied the SNI hostname into the buffer allocated from t...]]></description>
      <category>Security Research</category>
      <category>NGINX</category>
      <category>High</category>
      <category>CVE-2026-42533</category>
    </item>
    <item>
      <title><![CDATA[seroval.fromJSON() Promise resolver type confusion invokes attacker-controlled methods (CVE-2026-59940)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-59940</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-59940</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause `PromiseSuccess` and `PromiseFailure` nodes to operate on values from the general deserialization reference table without first verifying that those values were genuine internal promise resolver records. In vanilla `fromJSON()` mode, the serialized node tree and top-level `m` marked-reference list can place an attacker-created object in that table. The vulnerable handlers retrieved `refs[node.i]` and c...]]></description>
      <category>Security Research</category>
      <category>seroval</category>
      <category>Critical</category>
      <category>CVE-2026-59940</category>
    </item>
    <item>
      <title><![CDATA[gRPC forwarded headers can overflow the upstream HPACK request buffer (CVE-2026-42055)]]></title>
      <link>https://winfunc.com/hacktivity/nginx-grpc-forwarded-header-hpack-overflow</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/nginx-grpc-forwarded-header-hpack-overflow</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[When an HTTP/1.x request reaches a `grpc_pass` location, NGINX forwards client request headers by default. Before the fix, `ngx_http_grpc_create_request()` sized each forwarded header name and value with the fixed `NGX_HTTP_V2_INT_OCTETS` allowance of four HPACK integer bytes, then later serialized the same strings through the variable-length HPACK encoder.

If `ignore_invalid_headers off` allowed invalid raw-unfriendly header names to be retained, and `large_client_header_buffers` allowed multi...]]></description>
      <category>Security Research</category>
      <category>NGINX</category>
      <category>High</category>
      <category>CVE-2026-42055</category>
    </item>
    <item>
      <title><![CDATA[HTTP/2 upstream proxy request encoder permits heap overflow with oversized raw headers (CVE-2026-42055)]]></title>
      <link>https://winfunc.com/hacktivity/nginx-proxy-v2-forwarded-header-hpack-overflow</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/nginx-proxy-v2-forwarded-header-hpack-overflow</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[When `proxy_http_version 2` sends a request to an HTTP/2 upstream, `ngx_http_proxy_v2_create_request()` builds an HPACK-compressed request header block. Before the fix, the sizing pass used the same four-byte `NGX_HTTP_V2_INT_OCTETS` allowance for every forwarded header name and value length, but the serialization pass used the variable HPACK integer encoder.

A request with raw-encoded forwarded header names and values longer than `NGX_HTTP_V2_MAX_FIELD` makes the actual HPACK length prefix lar...]]></description>
      <category>Security Research</category>
      <category>NGINX</category>
      <category>High</category>
      <category>CVE-2026-42055</category>
    </item>
    <item>
      <title><![CDATA[rewrite overlapping captures heap overflow (CVE-2026-9256)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-9256</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-9256</guid>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[A regex rewrite such as `rewrite ^/((.*))$ http://127.0.0.1:18081/$1$2 redirect;` can make `$1` and `$2` cover the same attacker-controlled URI bytes. In NGINX 1.31.0 (`e8053c867f9ab14f323e3019ccab585d857abb66`), the rewrite compiler could discard the capture-aware length bytecode for capture-only replacements because `sc.variables == 0` and `sc.dup_capture == 0` when the replacement references distinct capture numbers.

At runtime, `ngx_http_script_regex_start_code()` then used its `code-&gt;lengt...]]></description>
      <category>Security Research</category>
      <category>NGINX</category>
      <category>High</category>
      <category>CVE-2026-9256</category>
    </item>
    <item>
      <title><![CDATA[HTTP/2 upstream frame injection via oversized proxy_set_body (CVE-2026-42926)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-42926</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-42926</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[When `proxy_http_version 2` selected the HTTP/2 upstream proxy path and `proxy_set_body` generated a custom request body, `ngx_http_proxy_v2_create_request()` appended that body directly after a single DATA frame header in the initial upstream buffer.

HTTP/2 frame lengths are 24-bit values. The vulnerable code stored `body_len` into `length_0`, `length_1`, and `length_2` without checking or fragmenting bodies larger than 16,777,215 bytes. If `proxy_set_body` produced a body over that limit, the...]]></description>
      <category>Security Research</category>
      <category>NGINX</category>
      <category>Medium</category>
      <category>CVE-2026-42926</category>
    </item>
    <item>
      <title><![CDATA[stream accepts revoked client certificates despite ssl_ocsp on (CVE-2026-28755)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-28755</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-28755</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[When a `stream` listener is configured with both `ssl_verify_client on` and `ssl_ocsp on`, nginx performs the OCSP request and learns that the presented client certificate is revoked, but it still completes the TLS handshake and allows the session to reach application data.

The root cause is a logic gap specific to `stream`: the OCSP helper records revocation state, but the `stream` verification path in `ngx_stream_ssl_handler()` checks only `SSL_get_verify_result()` and whether a certificate i...]]></description>
      <category>Security Research</category>
      <category>NGINX</category>
      <category>Medium</category>
      <category>CVE-2026-28755</category>
    </item>
    <item>
      <title><![CDATA[SCGI unbuffered mode sent truncated CONTENT_LENGTH causing backend desync]]></title>
      <link>https://winfunc.com/hacktivity/nginx-scgi-content-length-unbuffered</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/nginx-scgi-content-length-unbuffered</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[In the SCGI module, `ngx_http_scgi_create_request()` historically derived `CONTENT_LENGTH` by summing the currently buffered request-body chain (`r-&gt;upstream-&gt;request_bufs`). This behavior was introduced to support chunked-body accounting, but it becomes inaccurate when `scgi_request_buffering off` is used and the body is still streaming.

With unbuffered request forwarding, only an early body prefix may be available when SCGI headers are serialized. The emitted SCGI netstring can therefore adve...]]></description>
      <category>Security Research</category>
      <category>NGINX</category>
      <category>Medium</category>
      
    </item>
    <item>
      <title><![CDATA[WebDAV COPY/MOVE path overlap corrupts files and collections]]></title>
      <link>https://winfunc.com/hacktivity/nginx-dav-copy-move-path-overlap</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/nginx-dav-copy-move-path-overlap</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[The NGINX HTTP DAV module&apos;s `ngx_http_dav_copy_move_handler()` parsed the client-controlled `Destination` header and mapped both the request URI and destination URI to filesystem paths, but it did not validate that the resolved paths were distinct and non-overlapping.

If a `COPY` request targeted the same file path as its source, execution reached `ngx_copy_file(path.data, copy.path.data, &amp;cf)`. `ngx_copy_file()` opens the source first, then opens the destination with `NGX_FILE_TRUNCATE`; when ...]]></description>
      <category>Security Research</category>
      <category>NGINX</category>
      <category>High</category>
      
    </item>
    <item>
      <title><![CDATA[RSC reply decoder DoS via $K FormData amplification (CVE-2026-23864)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-23864</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-23864</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[The server-side React Flight reply decoder treats `$K&lt;id&gt;` tokens as **nested FormData** and reconstructs them by scanning the backing request form and copying entries into a new `FormData`. Because the decoder performs a full scan and allocation **for every `$K` occurrence** with no global limits, an attacker can embed thousands of `$K` tokens in a small multipart payload and force the server to allocate tens of MB of heap while decoding. This creates a high-amplification DoS that is remotely r...]]></description>
      <category>Security Research</category>
      <category>React</category>
      <category>High</category>
      <category>CVE-2026-23864</category>
    </item>
    <item>
      <title><![CDATA[Permission model bypass via unchecked Unix Domain Socket connections (CVE-2026-21636)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-21636</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-21636</guid>
      <pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[Node.js permission model **fails to enforce network restrictions for Unix Domain Socket (UDS) connections**. With `--permission` enabled and **without** `--allow-net` (or any allowlists), an attacker-controlled URL or `socketPath` still reaches arbitrary local sockets via `net`, `tls`, or `undici`/`fetch`. This breaks the security boundary the permission model is meant to provide and enables SSRF-to-local-RCE style impact against local daemons (e.g., Docker API) while the administrator believes ...]]></description>
      <category>Security Research</category>
      <category>Node.js</category>
      <category>Medium</category>
      <category>CVE-2026-21636</category>
    </item>
    <item>
      <title><![CDATA[Authentication bypass on FastMCP custom routes]]></title>
      <link>https://winfunc.com/hacktivity/anthropic-fastmcp-auth-bypass</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/anthropic-fastmcp-auth-bypass</guid>
      <pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[`FastMCP.custom_route()` allows developers to mount arbitrary HTTP handlers intended for sensitive use cases such as OAuth callbacks or admin APIs, but it never applies `RequireAuthMiddleware` even when the server is configured with a token verifier. Only the built-in SSE and StreamableHTTP endpoints are wrapped; custom routes are appended to the Starlette app as-is while Starlette’s `AuthenticationMiddleware` merely records credentials without rejecting unauthenticated requests. As a result any...]]></description>
      <category>Security Research</category>
      <category>Anthropic</category>
      <category>Critical</category>
      
    </item>
    <item>
      <title><![CDATA[SQL Injection via queueName in getDatabaseQueuesMetrics]]></title>
      <link>https://winfunc.com/hacktivity/supabase-sql-injection-via-queue-names</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/supabase-sql-injection-via-queue-names</guid>
      <pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[`getDatabaseQueuesMetrics` builds SQL statements with `queueName` interpolated directly into table identifiers and literals. The `queueName` value originates from the route parameter (`/integrations/queues/queues/:queueName`) which is attacker-controllable. No validation or quoting is applied before the SQL is sent to `executeSql`, allowing crafted queue names to break out of the identifier context and execute arbitrary SQL statements against the project database....]]></description>
      <category>Security Research</category>
      <category>Supabase</category>
      <category>Critical</category>
      
    </item>
    <item>
      <title><![CDATA[Exponential merge keys in Bun&apos;s YAML implementation leads to DoS]]></title>
      <link>https://winfunc.com/hacktivity/bun-yaml-dos</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/bun-yaml-dos</guid>
      <pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[`Bun.YAML.parse` materialises YAML mappings by iterating every merge (`&lt;&lt;`) entry and blindly appending the referenced property list to the target object (`src/bun.js/api/YAMLObject.zig:1034-1045`). Because the loop does not track merge depth or repeated anchors, an attacker can craft a document where each level merges all previous anchors (`&lt;&lt;: [*a0, *a1, …]`). The parser repeatedly copies the entire accumulated property array for each level, resulting in exponential work while the payload rema...]]></description>
      <category>Security Research</category>
      <category>Bun</category>
      <category>High</category>
      
    </item>
    <item>
      <title><![CDATA[0-click Account Takeover and Admin Operations via helper endpoint authorization bypass]]></title>
      <link>https://winfunc.com/hacktivity/gumroad-helper-auth-bypass-ato</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/gumroad-helper-auth-bypass-ato</guid>
      <pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[The helper endpoint responsible for updating user email addresses performs a sensitive account mutation without performing any authentication or authorization beyond confirming that an `Authorization` header exists. `Api::Internal::Helper::BaseController#verify_authorization_header!` only checks for the header’s presence and does not enforce a signature, token, or identity check unless an action explicitly invokes `authorize_hmac_signature!` or `authorize_helper_token!`. The `UsersController` ne...]]></description>
      <category>Security Research</category>
      <category>Gumroad</category>
      <category>Critical</category>
      
    </item>
    <item>
      <title><![CDATA[Remote cluster PATCH response leaked authentication tokens (CVE-2026-7184)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-7184</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-7184</guid>
      <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[Mattermost&apos;s remote-cluster API already treated `token` and `remote_token` as sensitive fields: list, create, accept, and get handlers called `RemoteCluster.Sanitize()` before serializing objects to clients. The PATCH handler was the missed trust boundary. After decoding a caller-controlled `RemoteClusterPatch` and applying it through `App.PatchRemoteCluster`, `patchRemoteCluster()` wrote `updatedRC` directly to the HTTP response without sanitizing it first.

The public advisory [MMSA-2026-00662...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>Medium</category>
      <category>CVE-2026-7184</category>
    </item>
    <item>
      <title><![CDATA[Group syncable scheme_admin authorization bypass (CVE-2026-7387)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-7387</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-7387</guid>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[Mattermost group syncables let LDAP groups be linked to teams or channels and can optionally mark synchronized group members as scheme admins. Before the fix, `linkGroupSyncable()` and `patchGroupSyncable()` decoded `scheme_admin` as ordinary patch data, checked only the permissions needed to link or patch the group syncable, and then persisted the flag. The background sync path later trusted that stored bit and updated team or channel member role state.

The public advisory [MMSA-2026-00665](ht...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>High</category>
      <category>CVE-2026-7387</category>
    </item>
    <item>
      <title><![CDATA[mmctl terminal escape injection via unsanitized server-controlled output (CVE-2026-3108)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-3108</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-3108</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[Mattermost&apos;s `mmctl` plain-text output path accumulated values from API responses and templates in `printer.Lines`, then wrote each line directly to stdout in `Printer.linesToBytes`. The report-posts command also bypassed the printer and wrote `post.Message` directly with `fmt.Fprintf(os.Stdout, ...)`. Because post messages and many other displayed fields can be controlled by ordinary users on the server being administered, a malicious value containing ANSI CSI sequences or OSC sequences could b...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>High</category>
      <category>CVE-2026-3108</category>
    </item>
    <item>
      <title><![CDATA[Zip bomb memory exhaustion in recursive document extraction (CVE-2026-3114)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-3114</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-3114</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[Mattermost enforces `FileSettings.MaxFileSize` on uploaded files, but the document extraction service previously did not apply that same limit to each decompressed archive entry. When file-content extraction and archive recursion were enabled, `archiveExtractor.Extract` mounted an uploaded archive, walked entries with `fs.WalkDir`, opened each entry, and called `io.ReadAll(file)` before handing the decompressed bytes to sub-extractors. A small compressed archive could therefore expand into very ...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>Medium</category>
      <category>CVE-2026-3114</category>
    </item>
    <item>
      <title><![CDATA[Group member IDs leaked because GetGroup bypassed view restrictions (CVE-2026-3115)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-3115</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-3115</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[The `GET /api/v4/groups/{group_id}` handler computed `ViewUsersRestrictions` for the session user and passed those restrictions into `App.GetGroup`. `GetGroup` correctly applied restrictions when returning `IncludeMemberCount`, but when `IncludeMemberIDs` was requested it called `Store().Group().GetMemberUsers(id)`, a raw unpaginated store method with no restrictions parameter. Guests or restricted users could therefore request a group with `include_member_ids=true` and receive member user IDs o...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>Medium</category>
      <category>CVE-2026-3115</category>
    </item>
    <item>
      <title><![CDATA[mmctl export downloads created world-readable local files (CVE-2026-3113)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-3113</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-3113</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[`mmctl export download` and related export download flows write potentially sensitive export archives to the administrator&apos;s local filesystem. The shared `downloadFile` helper used `os.Create(path)` when the destination did not exist, which creates files with mode `0666` before process umask is applied. On a common `022` umask, the resulting export file is `0644` and readable by other local users. When the destination already existed but was empty, `os.OpenFile(path, os.O_WRONLY, 0600)` did not ...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>Medium</category>
      <category>CVE-2026-3113</category>
    </item>
    <item>
      <title><![CDATA[Private channel enumeration through /mute error messages (CVE-2026-21386)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-21386</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-21386</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[The `/mute` slash command accepts an optional channel handle, strips the leading `~`, and looks up the named channel with `Store().Channel().GetByName(channel.TeamId, channelName, true)`. That lookup can resolve a private channel by name even when the caller is not a member. If the channel does not exist, the handler returns `api.command_mute.error`; if it exists but `ToggleMuteChannel` fails because the caller is not a member, the handler returned `api.command_mute.not_member.error`. Those two ...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>Medium</category>
      <category>CVE-2026-21386</category>
    </item>
    <item>
      <title><![CDATA[Oversized password login DoS in legacy password comparison (CVE-2026-24458)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-24458</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-24458</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[Mattermost validates password length when passwords are created or changed, but affected login comparison paths did not consistently apply the same maximum-length guard before invoking password verification. In modern 11.x branches, `App.checkUserPassword` parses the stored hash and dispatches to the matching hasher. PBKDF2 already enforced `PasswordMaxLengthBytes`, but the legacy bcrypt hasher&apos;s `CompareHashAndPassword` did not check input length before calling `bcrypt.CompareHashAndPassword`. ...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>High</category>
      <category>CVE-2026-24458</category>
    </item>
    <item>
      <title><![CDATA[User-Agent version parser panic during session creation (CVE-2026-25783)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-25783</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-25783</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[`DoLogin` parses the HTTP `User-Agent` header while creating a session and stores platform, OS, browser name, and browser version on the session. The version helper looked for Mattermost-specific prefixes such as `Mattermost Mobile/`, `Mattermost/`, `mmctl/`, and `Franz/`, then immediately returned `strings.Fields(afterVersion)[0]`. If the header ended at the prefix or contained only whitespace after it, `strings.Fields` returned an empty slice and the `[0]` index panicked.

This is not reached ...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>Medium</category>
      <category>CVE-2026-25783</category>
    </item>
    <item>
      <title><![CDATA[SSRF protection bypass via IPv4-mapped IPv6 literals (CVE-2026-2455)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2026-2455</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2026-2455</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[Mattermost&apos;s shared HTTP service protects untrusted outbound requests by resolving the target host and passing each IP through `allowIP`, which calls `IsReservedIP` and `IsOwnIP`. `IsReservedIP` contained IPv4 private, loopback, and link-local CIDRs, but it compared the raw `net.IP` value directly against those ranges. For an address such as `::ffff:127.0.0.1`, Go represents the value as an IPv4-mapped IPv6 address. Without canonicalization, the intended IPv4 reserved ranges could be bypassed an...]]></description>
      <category>Security Research</category>
      <category>Mattermost</category>
      <category>Medium</category>
      <category>CVE-2026-2455</category>
    </item>
    <item>
      <title><![CDATA[Multi-session sign-out hook allows forged cookies to revoke arbitrary sessions]]></title>
      <link>https://winfunc.com/hacktivity/better-auth-multi-session-signout-ato</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/better-auth-multi-session-signout-ato</guid>
      <pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[The `multiSession` plugin&apos;s `/sign-out` after-hook (`packages/better-auth/src/plugins/multi-session/index.ts`) blindly trusts every cookie whose name matches the `_multi-` pattern. The handler splits the first segment of each raw cookie value and forwards the resulting strings to `ctx.context.internalAdapter.deleteSessions(...)` without ever calling `ctx.getSignedCookie` or verifying an HMAC.

Because the Cookie header is entirely attacker-controlled, any authenticated user who learns another ac...]]></description>
      <category>Security Research</category>
      <category>Better-Auth</category>
      <category>Medium</category>
      
    </item>
    <item>
      <title><![CDATA[HTTP/1.1 CL.TE request smuggling in actix-http (GHSA-xhj4-vrgc-hr34)]]></title>
      <link>https://winfunc.com/hacktivity/GHSA-xhj4-vrgc-hr34</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/GHSA-xhj4-vrgc-hr34</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[The HTTP/1.1 request parser in `actix-http` accepted requests containing both `Content-Length` and `Transfer-Encoding: chunked`. During header conversion, `MessageType::set_headers` recorded the content length and also marked the message as chunked. The payload selection logic then preferred the chunked decoder whenever `chunked` was true, instead of rejecting the conflicting framing.

In a CL.TE deployment, an upstream proxy can frame the request using `Content-Length` while forwarding the ambi...]]></description>
      <category>Security Research</category>
      <category>Actix</category>
      <category>Medium</category>
      
    </item>
    <item>
      <title><![CDATA[Hoppscotch CLI sandbox escape through Node vm pre-request scripts (CVE-2024-34347)]]></title>
      <link>https://winfunc.com/hacktivity/CVE-2024-34347</link>
      <guid isPermaLink="true">https://winfunc.com/hacktivity/CVE-2024-34347</guid>
      <pubDate>Mon, 01 Jan 2024 00:00:00 GMT</pubDate>
      <author>Winfunc Research</author>
      <description><![CDATA[Hoppscotch CLI executes collection-supplied pre-request and test scripts while running `hopp test`. Unlike the web and desktop clients, the CLI could not rely on browser Web Workers and used the Node.js `vm` module through `@hoppscotch/js-sandbox`. The sandbox created a `vm` context, then injected host-created objects such as `pw`, `atob`, and `btoa` into that context before calling `runInContext` on attacker-controlled collection script text.

Node&apos;s `vm` module is not a security boundary for u...]]></description>
      <category>Security Research</category>
      <category>Hoppscotch</category>
      <category>High</category>
      <category>CVE-2024-34347</category>
    </item>
  </channel>
</rss>