Vulnerability Research

Protocol

  • CVE-2025-66624 (BACnet)
    Out-of-bounds vulnerability (CVSS 7.5)

Apache

  • CVE-2025-66524 (NiFi)
    Unsafe deserialization RCE (CVSS 7.5)
  • CVE-2025-67895 (Airflow)
    Edge3 Worker RPC RCE

Python Library

  • CVE-2025-67724 (Tornado)
    XSS via unescaped reason phrase (CVSS 6.1)
  • CVE-2025-67725 (Tornado)
    Event loop blocking DoS via HTTPHeaders.add (CVSS 7.5)
  • CVE-2025-67726 (Tornado)
    Quadratic DoS via multipart parameters (CVSS 7.5)
  • CVE-2025-69228 (aiohttp)
    Memory exhaustion DoS via Request.post() (CVSS 6.6)
  • CVE-2025-69229 (aiohttp)
    Blocking CPU DoS via chunked messages (CVSS 6.6)
  • CVE-2025-69230 (aiohttp)
    Cookie parser warning storm DoS (CVSS 6.5)

QEMU

  • CVE-2025-14876
    Denial of Service in virtio device emulation (CVSS 5.5)

Capstone

  • CVE-2025-68114 (Capstone Disassembler)
    Stack buffer overflow via vsnprintf (CVSS 4.8)
  • CVE-2025-67873 (Capstone Disassembler)
    Heap buffer overflow via skipdata callback (CVSS 4.8)

NASA

  • CVE-2026-21897 (CryptoLib)
    Out-of-bounds write in GVCID managed parameters (CVSS 7.3)
  • CVE-2026-21898 (CryptoLib)
    Out-of-bounds read in AOS frame parsing (CVSS 7.5)

EVerest

  • CVE-2026-27814
    Race condition in state machine loop (CVSS 4.2)
  • CVE-2026-26070
    Data race leading to std::map container corruption
  • CVE-2026-26071
    Data race leading to concurrent access heap use-after-free
  • CVE-2026-26072
    Data race leading to std::map<std::optional> corruption
  • CVE-2026-26073
    Data race leading to std::queue corruption
  • CVE-2026-26008
    Out-of-bounds read in energy transfer modes handling
  • CVE-2026-26074
    Data race leading to std::map<std::queue> corruption
  • CVE-2026-27813
    Use-after-free vulnerability from data race in plug-in events
  • CVE-2026-33009
    Race condition memory corruption in context access (CVSS 8.2)
  • CVE-2026-29044
    Timing flaw preventing session stop
  • CVE-2026-33014
    Authorization bypass during RemoteStop processing
  • CVE-2026-33015
    Logic flaw bypassing billing and safety controls
  • CVE-2026-22790
    Stack-based buffer overflow via SLAC payloads
  • CVE-2026-22593
    Stack-based buffer overflow in IsoMux certificate handling
  • CVE-2026-23995
    Stack-based buffer overflow in CAN interface initialization

Mobile Bug Bounty

  • Swiss Federal Railways (SBB) Mobile App
    Bug Bounty Reward: 800€