# heap overflow

Published articles for heap overflow.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Mongoose: Preauth RCE and mTLS Bypass on Millions of Devices

DevFeed: [Mongoose: Preauth RCE and mTLS Bypass on Millions of Devices](<https://devfeed.tech/articles/mongoose-preauth-rce-and-mtls-bypass-on-millions-of-devices-41273.md>)

Original publisher: [Read original article](<https://www.evilsocket.net/2026/04/02/Mongoose-Preauth-Remote-Code-Execution-and-mTLS-Bypass/>)

Author: Simone Margaritelli

Published: 2026-04-01T22:00:00Z

Content type: article

Language: en

Sources: [evilsocket](<https://devfeed.tech/sources/evilsocket.md>)

Topics: [Mongoose](<https://devfeed.tech/topics/mongoose.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [C](<https://devfeed.tech/topics/c.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [MQTT](<https://devfeed.tech/topics/mqtt.md>), [WebSocket](<https://devfeed.tech/topics/websocket.md>)

Tags: [authentication-bypass](<https://devfeed.tech/tags/authentication-bypass.md>), [buffer-overflow](<https://devfeed.tech/tags/buffer-overflow.md>), [c](<https://devfeed.tech/tags/c.md>), [cesanta](<https://devfeed.tech/tags/cesanta.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-5244](<https://devfeed.tech/tags/cve-2026-5244.md>), [cve-2026-5245](<https://devfeed.tech/tags/cve-2026-5245.md>), [cve-2026-5246](<https://devfeed.tech/tags/cve-2026-5246.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [embedded-devices](<https://devfeed.tech/tags/embedded-devices.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [heap-overflow](<https://devfeed.tech/tags/heap-overflow.md>), [http](<https://devfeed.tech/tags/http.md>), [https](<https://devfeed.tech/tags/https.md>), [industrial-control](<https://devfeed.tech/tags/industrial-control.md>), [iot](<https://devfeed.tech/tags/iot.md>), [iot-security](<https://devfeed.tech/tags/iot-security.md>), [library](<https://devfeed.tech/tags/library.md>), [mdns](<https://devfeed.tech/tags/mdns.md>), [mips](<https://devfeed.tech/tags/mips.md>), [mongoose](<https://devfeed.tech/tags/mongoose.md>), [mqtt](<https://devfeed.tech/tags/mqtt.md>), [mtls](<https://devfeed.tech/tags/mtls.md>), [rce](<https://devfeed.tech/tags/rce.md>), [responsible-disclosure](<https://devfeed.tech/tags/responsible-disclosure.md>), [security](<https://devfeed.tech/tags/security.md>), [stack-overflow](<https://devfeed.tech/tags/stack-overflow.md>), [tls](<https://devfeed.tech/tags/tls.md>), [vulnerability-research](<https://devfeed.tech/tags/vulnerability-research.md>)

### AI overview

The article reports three independently exploitable vulnerabilities in Mongoose v7.20, an embedded C networking library used in IoT devices: an mTLS authentication bypass, a preauthentication heap-overflow RCE through client public-key parsing, and a preauthentication RCE through mDNS over UDP. Mongoose v7.21 reportedly includes patches for the issues, which were assigned CVE-2026-5244, CVE-2026-5245, and CVE-2026-5246.

### Source excerpt

So, Mongoose. I

## exploits.club Weekly Newsletter 81 - Safari Spills, SonicWall Overflows, Pixel 8 KGDB, and More

DevFeed: [exploits.club Weekly Newsletter 81 - Safari Spills, SonicWall Overflows, Pixel 8 KGDB, and More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-81-safari-spills-sonicwall-overflows-pixel-8-kgdb-and-more-32638.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-81-safari-spills-sonicwall-overflows-pixel-8-kgdb-and-more/>)

Author: exploits.club

Published: 2025-08-07T15:00:14Z

Content type: news

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [browsers](<https://devfeed.tech/topics/browsers.md>), [Compiler](<https://devfeed.tech/topics/compiler.md>), [heap overflow](<https://devfeed.tech/topics/heap-overflow.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Android](<https://devfeed.tech/topics/android.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [debugging](<https://devfeed.tech/topics/debugging.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [compiler](<https://devfeed.tech/tags/compiler.md>), [cve](<https://devfeed.tech/tags/cve.md>), [debug](<https://devfeed.tech/tags/debug.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [heap-overflow](<https://devfeed.tech/tags/heap-overflow.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [weekly](<https://devfeed.tech/tags/weekly.md>)

### AI overview

The 81st exploits.club weekly newsletter rounds up security research and developer-oriented write-ups covering a Safari vulnerability, SonicWall SMA100 stack and heap overflows plus reflected XSS, and kernel debugging over a serial connection on a Pixel 8. It also mentions Project Zero disclosure guidelines, Pwn2Own Ireland, Phrack print copies, and an Interrupt Labs release.

### Source excerpt

Your friendly neighborhood editor will BE at HACKER SUMMER CAMP! Just look out for a beard, black t-shirt, and backpack...you won't miss me. Annnnnnnyways 👇 In Case You Missed It... Print Copies Of Phrack - Snag yours if you'll be at one of the events!

## The First F00D Exploit

DevFeed: [The First F00D Exploit](<https://devfeed.tech/articles/the-first-f00d-exploit-22355.md>)

Original publisher: [Read original article](<https://yifan.lu/2019/01/11/the-first-f00d-exploit/>)

Author: yifanlu

Published: 2019-01-11T08:00:00Z

Content type: article

Language: en

Sources: [Yifan Lu](<https://devfeed.tech/sources/yifan-lu.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [cpu](<https://devfeed.tech/topics/cpu.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [bigmac](<https://devfeed.tech/tags/bigmac.md>), [boot](<https://devfeed.tech/tags/boot.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [f00d](<https://devfeed.tech/tags/f00d.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [heap-overflow](<https://devfeed.tech/tags/heap-overflow.md>), [henkaku](<https://devfeed.tech/tags/henkaku.md>), [processor](<https://devfeed.tech/tags/processor.md>), [security](<https://devfeed.tech/tags/security.md>), [vita](<https://devfeed.tech/tags/vita.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [writeup](<https://devfeed.tech/tags/writeup.md>)

### AI overview

This technical article documents work on the first F00D exploit for the PlayStation Vita, including a memory-corruption vulnerability in a service and the role of F00D's private memory and cryptographic hardware accelerator.

### Source excerpt

This article was originally written 2019-01-11 and published on 2019-07-29 for the third anniversary of HENkaku, the first Vita jailbreak. It documents the work we did in early 2017, just days after the seminal "octopus" exploit. Although the work is dated and does not open any new doors, the technical contents might be interesting for a particular audience. The original intention was to post this after someone else independently discovers the same vulnerability. There were many overt hints on the HENkaku wiki that the 0x50002 service was buggy but I underestimated the interest (or skills) that people would have in hacking an exotic processor that ultimately does nothing for people who just want to run homebrews or play pirated games.