Tootfinder

Opt-in global Mastodon full text search. Join the index!

@adulau@infosec.exchange
2025-12-03 19:57:37

“A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.“
#vulnerability

@adulau@infosec.exchange
2025-10-04 06:48:40

OpenSSL Security Advisory [30th September 2025]
#openssl #vulnerability

@adulau@infosec.exchange
2025-12-06 16:10:40

We’ve updated the draft GCVE BCP-05 standard to introduce flexible record types, making it easier to extend, enrich, and structure security advisories.
Comments are more than welcome!
#gcve #cve #vulnerability

@publicvoit@graz.social
2025-09-18 06:41:46

"While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful #EntraID #vulnerability that I will probably ever find. This vulnerability could have allowed me to compromise every Entra ID tenant in the world (except probably those in national cloud deploymen…

@frankel@mastodon.top
2025-11-11 17:30:05

#Redis Critical Remote Code Execution #Vulnerability Discovered After 13 Years
infoq.com/news/2025…

@adulau@infosec.exchange
2025-11-08 14:25:05

We presented “Advancing Vulnerability Tracking and Disclosure Through an Open and Distributed Platform” at the excellent @…
#cve #vulnerability

@adulau@infosec.exchange
2025-10-24 09:02:02

Vulnerability Lookup and GCVE: A Decentralized Approach to Vulnerability Publishing and Management Workshop at Hack.lu 2025
We published all the materials from the workshop given at #hacklu 2025
#gcve

Overview of vulnerability-lookup