# remote code execution

Published articles for remote code execution.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## \[webapps\] Metabase 0.61.0 - Authenticated Remote Code Execution

DevFeed: [\[webapps\] Metabase 0.61.0 - Authenticated Remote Code Execution](<https://devfeed.tech/articles/webapps-metabase-0-61-0-authenticated-remote-code-execution-34773.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52680>)

Author: Gutierre0x80

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-59827](<https://devfeed.tech/tags/cve-2026-59827.md>), [execution](<https://devfeed.tech/tags/execution.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote](<https://devfeed.tech/tags/remote.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit-DB entry identifies authenticated remote code execution affecting Metabase 0.61.0 and associates it with CVE-2026-59827.

### Source excerpt

Metabase 0.61.0 - Authenticated Remote Code Execution

## \[webapps\] FreePBX 17.0.2 - Remote Code Execution (RCE)

DevFeed: [\[webapps\] FreePBX 17.0.2 - Remote Code Execution (RCE)](<https://devfeed.tech/articles/webapps-freepbx-17-0-2-remote-code-execution-rce-34774.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52681>)

Author: Jared Brits

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-57819](<https://devfeed.tech/tags/cve-2025-57819.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry describing remote code execution affecting FreePBX 17.0.2, associated with CVE-2025-57819.

### Source excerpt

FreePBX 17.0.2 - Remote Code Execution (RCE)

## \[webapps\] Ghost\_CMS 6.19.0 - Remote Code Execution

DevFeed: [\[webapps\] Ghost\_CMS 6.19.0 - Remote Code Execution](<https://devfeed.tech/articles/webapps-ghost-cms-6-19-0-remote-code-execution-34769.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52676>)

Author: Maksim Rogov

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-29053](<https://devfeed.tech/tags/cve-2026-29053.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry identifies a remote code execution exploit affecting Ghost_CMS 6.19.0, associated with CVE-2026-29053 and listed for multiple platforms.

### Source excerpt

Ghost_CMS 6.19.0 - Remote Code Execution

## \[webapps\] Langflow 1.8.4 - Path Traversal to Remote Code Execution

DevFeed: [\[webapps\] Langflow 1.8.4 - Path Traversal to Remote Code Execution](<https://devfeed.tech/articles/webapps-langflow-1-8-4-path-traversal-to-remote-code-execution-34752.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52659>)

Author: cardosource

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-5027](<https://devfeed.tech/tags/cve-2026-5027.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit record identifies a path traversal vulnerability in Langflow 1.8.4 that can lead to remote code execution. It references CVE-2026-5027.

### Source excerpt

Langflow 1.8.4 - Path Traversal to Remote Code Execution

## Vercel applications are protected from Next.js August 2026 security vulnerabilities

DevFeed: [Vercel applications are protected from Next.js August 2026 security vulnerabilities](<https://devfeed.tech/articles/vercel-applications-are-protected-from-next-js-august-2026-security-vulnerabilities-1028.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/nextjs-august-2026-security-release>)

Author: Karim Rahal

Published: 2026-08-25T16:39:17Z

Content type: article

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Next.js](<https://devfeed.tech/topics/next-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>), [AVIF Images](<https://devfeed.tech/topics/avif-images.md>), [Cache](<https://devfeed.tech/topics/cache.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [avif-images](<https://devfeed.tech/tags/avif-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [linux](<https://devfeed.tech/tags/linux.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Vercel reports two critical Next.js vulnerabilities disclosed in the August 2026 Security Release. Vercel-hosted applications are protected without customer action, while self-hosted applications should upgrade to patched versions.

### Source excerpt

Summary Two vulnerabilities affecting Next.js were disclosed in the August 2026 Security Release. Next.js applications hosted on Vercel are protected and require no customer action. Next.js August 2026 vulnerabilities Next.js disclosed the following critical vulnerabilities: GHSA-2xp9-vwfh-vxw4 originates in the upstream libheif dependency and can lead to unauthenticated remote code execution when Image Optimization processes a crafted AVIF input. CVE-2026-75604 (GHSA-p293-qw3h-jr36) can lead to unauthenticated remote code execution on Windows-hosted Next.js servers in applications using the Pages Router and App Router without Cache Components. After the AVIF vulnerability was identified, Vercel applied protections to its managed Image Optimization service. Impact on Vercel deployments Applications hosted on Vercel are protected. No upgrades, configuration changes, or redeploys are required. Once the AVIF vulnerability was identified, Vercel disabled AVIF optimization across its managed Image Optimization service. AVIF inputs are served as-is and do not pass through the affected processing path. The second vulnerability only affects servers using a Windows filesystem. Vercel's Next.js runtime uses Linux and is not affected. Resolution for self-hosted applications Self-hosted Next.js applications should upgrade to the appropriate patched version. For applications running Next.js 15.x or earlier: For applications running Next.js 16.x: In the patched releases, AVIF images are not resized or optimized. They are served as-is until a fixed libheif version is available. There is no workaround for the Windows vulnerability; affected servers should upgrade immediately. Credit Thanks to the Hacktron team for responsibly disclosing the AVIF vulnerability, and to evolutionstorm and B0RI for responsibly disclosing the Windows vulnerability. References Next.js August 2026 security release GHSA-2xp9-vwfh-vxw4 Upstream libheif advisory GHSA-p293-qw3h-jr36 Read more

## \[webapps\] Joomla JCE\_2.9.15 - Remote Code Execution

DevFeed: [\[webapps\] Joomla JCE\_2.9.15 - Remote Code Execution](<https://devfeed.tech/articles/webapps-joomla-jce-2-9-15-remote-code-execution-34738.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52645>)

Author: Jared Brits

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-48907](<https://devfeed.tech/tags/cve-2026-48907.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

A record describing a remote code execution exploit affecting Joomla JCE 2.9.15, identified as CVE-2026-48907 and categorized under web applications for multiple platforms.

### Source excerpt

Joomla JCE_2.9.15 - Remote Code Execution

## \[remote\] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution

DevFeed: [\[remote\] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution](<https://devfeed.tech/articles/remote-praisonai-praisonaiagents-1-6-77-remote-code-execution-34732.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52639>)

Author: banyamer

Published: 2026-08-11T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-61447](<https://devfeed.tech/tags/cve-2026-61447.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote](<https://devfeed.tech/tags/remote.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>)

### AI overview

This entry reports a remote code execution exploit affecting PraisonAI praisonaiagents version 1.6.77, identified as CVE-2026-61447.

### Source excerpt

PraisonAI praisonaiagents 1.6.77 - Remote Code Execution

## Nuxt July 2026 security advisory

DevFeed: [Nuxt July 2026 security advisory](<https://devfeed.tech/articles/nuxt-july-2026-security-advisory-1033.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/nuxt-july-2026-security-advisory>)

Author: Sage Abraham

Published: 2026-07-27T00:00:00Z

Content type: article

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Nuxt.js](<https://devfeed.tech/topics/nuxt.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [cache](<https://devfeed.tech/tags/cache.md>), [caching](<https://devfeed.tech/tags/caching.md>), [cve](<https://devfeed.tech/tags/cve.md>), [development](<https://devfeed.tech/tags/development.md>), [nuxt](<https://devfeed.tech/tags/nuxt.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The Nuxt team released Nuxt 4.5.1, Nuxt 3.21.10, and @nuxt/devtools 3.3.1 to fix eight security advisories, including a high-severity server-side remote code execution vulnerability. Vercel deployed WAF mitigations for direct exploitation of that vulnerability, but users must still upgrade because other issues affect component instantiation, caching, authorization, denial of service, and development tooling.

### Source excerpt

The Nuxt team has released Nuxt 4.5.1 and 3.21.10, along with @nuxt/devtools 3.3.1, to address eight security advisories, including a high-severity server-side remote code execution vulnerability. Vulnerabilities addressed Vulnerability Severity Advisory Server-side remote code execution via server island props High GHSA-9473-5f9j-94wq Unauthorized component instantiation via server island props Medium GHSA-48hr-524c-v5w3 Route rule authorization bypass High GHSA-hxvh-4h3w-prp9 Server component denial of service High GHSA-hxcr-hm88-mpq6, GHSA-9pgf-384g-p7mv Cross-user disclosure of cached payloads, affecting Nuxt 4.x versions 4.4.0 and later High GHSA-wm8w-6qjm-cv43 Development server path disclosure Low GHSA-7c4v-fwgw-9rf7 Remote code execution in Nuxt DevTools, development-only, fixed in @nuxt/devtools 3.3.1 Critical GHSA-279x-mwfv-vcqv Vercel platform protections Vercel received advance notice of the server-side remote code execution vulnerability, GHSA-9473-5f9j-94wq, and deployed platform-wide WAF mitigations before public disclosure. Applications deployed on Vercel are automatically protected by these mitigations, with no configuration changes required. However, do not rely on them for full protection. Upgrading to a patched version is still required. The WAF mitigations cover only direct exploitation of the server-side RCE. The remaining component-instantiation, caching, authorization, denial-of-service, and development-time vulnerabilities require upgrading Nuxt and Nuxt DevTools. Recommended action All Nuxt users should upgrade as soon as possible: Nuxt 4: 4.5.1 or later Nuxt 3: 3.21.10 or later Nuxt DevTools: 3.3.1 or later To upgrade, run: This also refreshes the lockfile, pulling in the patched Nuxt DevTools version. Users who previously upgraded for the earlier route rule advisory, CVE-2026-53721, must still upgrade. The newly disclosed authorization bypass is a regression in that earlier fix. Nuxt 4 users who cache authenticated pages containing user-s

## Mitigating WordPress attacks with containers

DevFeed: [Mitigating WordPress attacks with containers](<https://devfeed.tech/articles/mitigating-wordpress-attacks-with-containers-13164.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mitigating-wordpress-attacks-with-containers>)

Published: 2026-07-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [WordPress](<https://devfeed.tech/topics/wordpress.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [containers](<https://devfeed.tech/tags/containers.md>), [database](<https://devfeed.tech/tags/database.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [files](<https://devfeed.tech/tags/files.md>), [hardened-containers](<https://devfeed.tech/tags/hardened-containers.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wordpress](<https://devfeed.tech/tags/wordpress.md>), [wordpress-cves](<https://devfeed.tech/tags/wordpress-cves.md>)

### AI overview

This article examines the wp2shell attack, in which two WordPress vulnerabilities can be chained to achieve remote code execution. It explains that hardened, distroless containers and read-only filesystems can limit an attacker's capabilities and simplify recovery, while emphasizing the need to update WordPress immediately.

### Source excerpt

The wp2shell WordPress exploit enables remote code execution. Learn how hardened containers help reduce the blast radius of compromise.

## Bringing Rust to the Pixel Baseband

DevFeed: [Bringing Rust to the Pixel Baseband](<https://devfeed.tech/articles/bringing-rust-to-the-pixel-baseband-19818.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2026/04/bringing-rust-to-pixel-baseband.html>)

Author: Edward Fernandez (noreply@blogger.com)

Published: 2026-04-10T15:12:00Z

Content type: article

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [Rust](<https://devfeed.tech/topics/rust.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [Security](<https://devfeed.tech/topics/security.md>), [Parsing](<https://devfeed.tech/topics/parsing.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [dns](<https://devfeed.tech/tags/dns.md>), [google](<https://devfeed.tech/tags/google.md>), [internet](<https://devfeed.tech/tags/internet.md>), [library](<https://devfeed.tech/tags/library.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [none](<https://devfeed.tech/tags/none.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [parsing](<https://devfeed.tech/tags/parsing.md>), [pixel](<https://devfeed.tech/tags/pixel.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [rust](<https://devfeed.tech/tags/rust.md>), [security](<https://devfeed.tech/tags/security.md>), [test-coverage](<https://devfeed.tech/tags/test-coverage.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Google describes integrating a memory-safe Rust DNS parser into Pixel modem firmware. The post explains the security motivation, the modem's remote attack surface, and the evaluation of open-source Rust DNS libraries, identifying hickory-proto as the best candidate based on maintenance, test coverage, and adoption.

### Source excerpt

Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities. For Pixel 10, Google is advancing its proactive security measures further. Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware. The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of vulnerabilities in a risky area, while also laying the foundation for broader adoption of memory-safe code in other areas. Here we share our experience of working on it, and hope it can inspire the use of more memory safe languages in low-level environments. Why Modem Memory Safety Can't Wait In recent years, we have seen increasing interest in the cellular modem from attackers and security researchers. For example, Google's Project Zero gained remote code execution on Pixel modems over the Internet. Pixel modem has tens of Megabytes of executable code. Given the complexity and remote attack surface of the modem, other critical memory safety vulnerabilities may remain in the predominantly memory-unsafe firmware code. Why DNS? The DNS protocol is most commonly known in the context of browsers finding websites. With the evolution of cellular technology, modern cellular communications have migrated to digital data networks; consequently, even basic operations such as call forwarding rely on DNS services. DNS is a complex protocol and requires parsing of untrusted data, which can lead to vulnerabilities, particularly when implemented in a memory-unsafe language (example: CVE-2024-27227). Implementing the DNS parser in Rust offers va

## exploits.club Weekly(ish) Newsletter 94 - P20 VMWare Bugs, ExpDev With LLMs, Pixel 0-Click Bugs, and More

DevFeed: [exploits.club Weekly(ish) Newsletter 94 - P20 VMWare Bugs, ExpDev With LLMs, Pixel 0-Click Bugs, and More](<https://devfeed.tech/articles/exploits-club-weekly-ish-newsletter-94-p20-vmware-bugs-expdev-with-llms-pixel-0-click-bugs-and-more-32636.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-ish-newsletter-94-p20-vmware-bugs-expdev-with-llms-pixel-0-click-bugs-and-more/>)

Author: exploits.club

Published: 2026-01-30T16:00:22Z

Content type: article

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Code](<https://devfeed.tech/topics/code.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Network architectures](<https://devfeed.tech/topics/network-architectures.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [code](<https://devfeed.tech/tags/code.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [linux](<https://devfeed.tech/tags/linux.md>), [llms](<https://devfeed.tech/tags/llms.md>), [network](<https://devfeed.tech/tags/network.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [peer](<https://devfeed.tech/tags/peer.md>), [poc](<https://devfeed.tech/tags/poc.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This newsletter surveys recent security research, including experiments using Claude and ChatGPT to generate proofs of concept for QuickJS vulnerabilities, a wormable remote code execution chain in Command & Conquer, a MediaTek bootloader exploit, and VMware workstation research.

### Source excerpt

Good morning friends....been a minute. But we are SO back. Annnnnyways 👇 In Case You Missed It... RE//verse Tickets Still On Sale - If you were just at DistrictCon, escape the snow-pocalypse to Florida next month OffensiveCon CFP - 30 days to get-em submitted! Resources And Write-Ups

## Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component

DevFeed: [Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component](<https://devfeed.tech/articles/revisiting-cve-2025-50165-a-critical-flaw-in-windows-imaging-component-8380.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/revisiting-cve-2025-50165-critical-flaw-windows-imaging-component/>)

Author: Romain Dumont

Published: 2025-12-22T09:55:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Code](<https://devfeed.tech/topics/code.md>), [Library](<https://devfeed.tech/topics/library.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [cve](<https://devfeed.tech/tags/cve.md>), [deep-dive](<https://devfeed.tech/tags/deep-dive.md>), [encoding](<https://devfeed.tech/tags/encoding.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [jpeg](<https://devfeed.tech/tags/jpeg.md>), [library](<https://devfeed.tech/tags/library.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [root-cause-analysis](<https://devfeed.tech/tags/root-cause-analysis.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET analyzes CVE-2025-50165, a critical Windows Imaging Component vulnerability in WindowsCodecs.dll. The flaw involves an uninitialized function-pointer dereference during JPG compression and re-encoding, and the article reassesses how difficult the vulnerability is to exploit.

### Source excerpt

A comprehensive analysis and assessment of a critical severity vulnerability with low likelihood of mass exploitation

## Security Advisory: CVE-2025-66478

DevFeed: [Security Advisory: CVE-2025-66478](<https://devfeed.tech/articles/security-advisory-cve-2025-66478-3134.md>)

Original publisher: [Read original article](<https://nextjs.org/blog/CVE-2025-66478>)

Author: Sebastian Markbåge

Published: 2025-12-03T16:00:00Z

Content type: article

Language: en

Sources: [Next.js Blog](<https://devfeed.tech/sources/next-js-blog.md>)

Topics: [Next.js](<https://devfeed.tech/topics/next-js.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [React](<https://devfeed.tech/topics/react.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [react](<https://devfeed.tech/tags/react.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This security advisory describes CVE-2025-66478, a critical vulnerability in the React Server Components protocol that affects certain Next.js applications using the App Router. Under specific conditions, attacker-controlled requests could lead to remote code execution. Users are advised to upgrade to patched Next.js releases immediately.

### Source excerpt

A critical vulnerability (CVE-2025-66478) has been identified in the React Server Components protocol. Users should upgrade to patched versions immediately.

## Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)

DevFeed: [Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)](<https://devfeed.tech/articles/security-advisory-critical-rce-vulnerabilities-in-react-server-components-cve-2025-55182-8087.md>)

Original publisher: [Read original article](<https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/>)

Author: Stephen Thoemmes

Published: 2025-12-03T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [React](<https://devfeed.tech/topics/react.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Next.js](<https://devfeed.tech/topics/next-js.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Security](<https://devfeed.tech/topics/security.md>), [Flight](<https://devfeed.tech/topics/flight.md>), [HTTP](<https://devfeed.tech/topics/http.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [docker](<https://devfeed.tech/tags/docker.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [http](<https://devfeed.tech/tags/http.md>), [incident](<https://devfeed.tech/tags/incident.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [react](<https://devfeed.tech/tags/react.md>), [remote](<https://devfeed.tech/tags/remote.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

The article reports critical unauthenticated remote code execution vulnerabilities in React Server Components and Next.js caused by unsafe deserialization of attacker-controlled data in the RSC "Flight" protocol. It explains that default configurations were exploitable, identifies affected React and Next.js releases and other tools embedding RSC, and urges immediate patching.

### Source excerpt

Critical RCE vulnerabilities (CVE-2025-55182/CVE-2025-66478) were found in React Server Components and Next.js via unsafe deserialization. Immediate upgrade to patched versions is mandatory to prevent unauthenticated remote code execution. Learn how to detect and mitigate the critical flaw.

## Microauthorization: Why Microservices can be Great for Security Hygiene

DevFeed: [Microauthorization: Why Microservices can be Great for Security Hygiene](<https://devfeed.tech/articles/microauthorization-why-microservices-can-be-great-for-security-hygiene-13156.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/microauthorization-why-microservices-can-be-great-for-security-hygiene>)

Published: 2025-05-08T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [microservices architecture](<https://devfeed.tech/topics/microservices-architecture.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [IAM](<https://devfeed.tech/topics/iam.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [iam](<https://devfeed.tech/tags/iam.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [microauthorization](<https://devfeed.tech/tags/microauthorization.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that decomposing monolithic applications into microservices can improve security hygiene by isolating processes and assigning each service a distinct identity with narrower IAM capabilities. It explains that service-to-service authorization can limit the blast radius of a breach, although attackers may still need to move laterally across services.

### Source excerpt

Microservices can enable you to easily independently roll out services, but they can also provide security benefits. Learn more with Chainguard CTO Matt Moore.

## Ingress-nginx-controller: Nightmare on CVE Street

DevFeed: [Ingress-nginx-controller: Nightmare on CVE Street](<https://devfeed.tech/articles/ingress-nginx-controller-nightmare-on-cve-street-13103.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ingress-nginx-controller-nightmare-on-cve-street>)

Published: 2025-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [nginx](<https://devfeed.tech/topics/nginx.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [ingress](<https://devfeed.tech/tags/ingress.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wiz](<https://devfeed.tech/tags/wiz.md>)

### AI overview

The article describes several critical remote code execution vulnerabilities affecting the Ingress-nginx-controller, including risks to Kubernetes cluster secrets, service availability, privileges, and security controls. It also explains how Chainguard reviewed its infrastructure, identified affected Chainguard Containers, and prepared patches using Chainguard OS's continuous update model.

### Source excerpt

Chainguard was able to quickly respond to and handle the recent ingress-nginx-controller CVEs that were discovered by Wiz. See the actions we have taken.

## Zero-day RCE vulnerability found in CUPS - Common UNIX Printing System

DevFeed: [Zero-day RCE vulnerability found in CUPS - Common UNIX Printing System](<https://devfeed.tech/articles/zero-day-rce-vulnerability-found-in-cups-common-unix-printing-system-8260.md>)

Original publisher: [Read original article](<https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/>)

Author: Jim Armstrong

Published: 2024-09-27T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Unix](<https://devfeed.tech/topics/unix.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [C](<https://devfeed.tech/topics/c.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c](<https://devfeed.tech/tags/c.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dns](<https://devfeed.tech/tags/dns.md>), [docker](<https://devfeed.tech/tags/docker.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [executive](<https://devfeed.tech/tags/executive.md>), [interest](<https://devfeed.tech/tags/interest.md>), [linux](<https://devfeed.tech/tags/linux.md>), [network](<https://devfeed.tech/tags/network.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [port](<https://devfeed.tech/tags/port.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [scm](<https://devfeed.tech/tags/scm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article reports several vulnerabilities in CUPS, the Common UNIX Printing System, including unauthenticated remote code execution. It discusses four associated CVEs, a potentially high CVSS score, affected UNIX and Linux packages, exploitability conditions involving UDP port 631 or DNS-SD, and remediation assessment using Snyk Open Source and Snyk Container.

### Source excerpt

Security researcher evilsocket.net (Simone Margaritelli) published information about several vulnerabilities in CUPS that allow for remote code execution (RCE)

## Understanding attacker techniques in distroless containers

DevFeed: [Understanding attacker techniques in distroless containers](<https://devfeed.tech/articles/understanding-attacker-techniques-in-distroless-containers-13300.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/understanding-attacker-techniques-in-distroless-containers>)

Published: 2023-10-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [distroless-containers](<https://devfeed.tech/tags/distroless-containers.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article examines attacker techniques relevant to distroless containers, drawing on a DEFCON 31 talk and an example involving PHP remote code execution, reverse shells, and injected spam content. It emphasizes keeping software up to date and using defense in depth.

### Source excerpt

Explore DEFCON 31 insights on Distroless container security. Delve into RCE vulnerabilities and Chainguard's robust defense strategies for up-to-date software.

## Swift deserialization security primer

DevFeed: [Swift deserialization security primer](<https://devfeed.tech/articles/swift-deserialization-security-primer-8198.md>)

Original publisher: [Read original article](<https://snyk.io/blog/swift-deserialization-security-primer/>)

Author: Sam Sanoop

Published: 2023-07-18T16:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Swift](<https://devfeed.tech/topics/swift.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Code](<https://devfeed.tech/topics/code.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [distributed](<https://devfeed.tech/tags/distributed.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [serialization](<https://devfeed.tech/tags/serialization.md>), [swift](<https://devfeed.tech/tags/swift.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This Swift security primer explains how deserialization vulnerabilities can arise when using NSCoding and NSSecureCoding. It describes object substitution attacks, potential remote code execution, command injection, and stricter protections provided by NSSecureCoding.

### Source excerpt

This blog will detail deserialization vulnerabilities in Swift that can occur when using the popular APIs, NScoding and NSSecureCoding, and how to prevent it properly.

## Making Open Source Safer for Everyone with Shopify's Bug Bounty Program

DevFeed: [Making Open Source Safer for Everyone with Shopify's Bug Bounty Program](<https://devfeed.tech/articles/making-open-source-safer-for-everyone-with-shopify-s-bug-bounty-program-1599.md>)

Original publisher: [Read original article](<https://shopify.engineering/shopify-making-open-source-safer>)

Author: Zack Deveau

Published: 2022-06-15T18:00:02Z

Content type: article

Language: en

Sources: [Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering.md>), [Shopify Engineering - Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering-shopify-engineering.md>)

Topics: [Shopify](<https://devfeed.tech/topics/shopify.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Rails](<https://devfeed.tech/topics/rails.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [rails](<https://devfeed.tech/tags/rails.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [serialization](<https://devfeed.tech/tags/serialization.md>), [shopify](<https://devfeed.tech/tags/shopify.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Shopify describes how a bug bounty report led to contributions that improve the security of the Rails library. The report identified a deserialization vulnerability in ActiveSupport's MessageEncryptor, where leaked development secrets could enable seemingly trusted data and potentially remote code execution. Shopify addressed the issue in its system, helped Rails adopt safer default serializers, and developed tools to help Ruby application developers identify similar risks.

### Source excerpt

Zack Deveau, Senior Application Security Engineer at Shopify, shares the details behind a recent contribution to the Rails library, inspired by a bug bounty report we received. He'll go over the report and its root cause, how we fixed it in our system, and how we took it a step further to make Rails more secure by updating the default serializer for a few classes to use safe defaults.

## Log4j Vulnerability Update

DevFeed: [Log4j Vulnerability Update](<https://devfeed.tech/articles/log4j-vulnerability-update-3873.md>)

Original publisher: [Read original article](<https://laravel.com/blog/log4j-vulnerability-update>)

Author: James Brooks

Published: 2021-12-15T13:14:00Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Java](<https://devfeed.tech/topics/java.md>), [Library](<https://devfeed.tech/topics/library.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [Laravel](<https://devfeed.tech/topics/laravel.md>)

Tags: [apache](<https://devfeed.tech/tags/apache.md>), [docker](<https://devfeed.tech/tags/docker.md>), [elasticsearch](<https://devfeed.tech/tags/elasticsearch.md>), [java](<https://devfeed.tech/tags/java.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [library](<https://devfeed.tech/tags/library.md>), [log4j](<https://devfeed.tech/tags/log4j.md>), [news](<https://devfeed.tech/tags/news.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [script](<https://devfeed.tech/tags/script.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This update explains the Log4Shell vulnerability in Apache Log4j, a Java logging library that can allow remote code execution through a specific string. Laravel Forge and Laravel Vapor do not install or use Log4j by default, but manually installed applications, libraries, custom layers, or customized environments may still be affected and should be checked.

### Source excerpt

Log4j is a Java library by Apache used to log debug messages within applications. It's recently been featured in news outlets around the world due to a vulnerability (known as Log4Shell) that was discovered allowing remote code execution using a specific string.

## Dealing with the Critical Log4j Vulnerability

DevFeed: [Dealing with the Critical Log4j Vulnerability](<https://devfeed.tech/articles/dealing-with-the-critical-log4j-vulnerability-24668.md>)

Original publisher: [Read original article](<https://blog.gradle.org/log4j-vulnerability>)

Author: Kyle Moore

Published: 2021-12-13T05:00:00Z

Content type: tutorial

Language: en

Sources: [The Gradle Blog](<https://devfeed.tech/sources/the-gradle-blog.md>)

Topics: [log4j](<https://devfeed.tech/topics/log4j.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [CVE-2021-44228](<https://devfeed.tech/topics/cve-2021-44228.md>), [Gradle](<https://devfeed.tech/topics/gradle.md>), [Logging](<https://devfeed.tech/topics/logging.md>)

Tags: [apache](<https://devfeed.tech/tags/apache.md>), [cve-2021-44228](<https://devfeed.tech/tags/cve-2021-44228.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [log4j](<https://devfeed.tech/tags/log4j.md>), [logging](<https://devfeed.tech/tags/logging.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This advisory explains the critical remote code execution vulnerability in Apache Log4j, identifies affected versions, and provides Gradle users with steps to detect vulnerable dependencies, upgrade Log4j, and protect project and build dependencies. It also clarifies that the Gradle Build Tool itself does not use Log4j.

### Source excerpt

A critical remote code execution (RCE) vulnerability has been identified in the popular Apache Log4j logging library that affects versions 2.0 up to and including 2.14.1. This vulnerability has affected a very large number of JVM-based systems. For more information on the vulnerability itself, see CVE-2021-44228. Update (December 22, 2021): Since the first post, two other vulnerabilities have been identified - CVE-2021-45046 and CVE-2021-45105 - so make sure to go over the different sections for updated instructions. This vulnerability is being actively exploited. All Gradle users should assess whether their software projects are vulnerable and, if necessary, update to Log4j 2.17.0 or newer as soon as possible. We have provided instructions below on how to identify and prevent this vulnerability in your project. We strongly recommended that you configure your Gradle build to reject any vulnerable version of Log4j using a dependency constraint. In addition to your project dependencies, we also recommend protecting your build dependencies as documented below. Note that the Gradle Build Tool itself is not impacted by this vulnerability as it does not use Log4j. Gradle uses SLF4J and a custom logging implementation not susceptible to the vulnerable string substitution. The Gradle Scala plugin uses the Zinc Scala compiler that has a dependency on a vulnerable version of Log4j. However, in this case Gradle also supplies its own logging implementation and Log4j is not used by default. Updates to this post: Updated on December 14th Updated on December 15th Updated on December 22nd Updated on December 30th Protecting your project dependencies 1. Identify if your project uses a vulnerable Log4j version First, verify if your project uses the vulnerable Log4j version using the dependencies report or a Build Scan™. See viewing and debugging dependencies for details. All versions of org.apache.logging.log4j:log4j-core between 2.0 and 2.16.0 (inclusive) are vulnerable. 2. Upgrade

## How a malicious pull request could expose cloud infrastructure credentials

DevFeed: [How a malicious pull request could expose cloud infrastructure credentials](<https://devfeed.tech/articles/how-to-attack-cloud-infrastructure-via-a-malicious-pull-request-29669.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/hack-via-pull-request/>)

Author: info@goteleport.com (Walt Della)

Published: 2021-09-16T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [docker](<https://devfeed.tech/tags/docker.md>), [github](<https://devfeed.tech/tags/github.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This blog post analyzes a vulnerability in Teleport's former CI environment in which code from an unapproved external pull request could escape isolation, pivot through Kubernetes workloads to CI infrastructure, and expose production AWS credentials. The article says the CI system was fixed and that the response team found no evidence of exploitation or data tampering.

### Source excerpt

In this blog post we'll explain how an attacker can get access into a cloud environment by sending a malicious pull request.

## Proxies are complicated: RCE vulnerability in a 3 million downloads/week NPM package

DevFeed: [Proxies are complicated: RCE vulnerability in a 3 million downloads/week NPM package](<https://devfeed.tech/articles/proxies-are-complicated-rce-vulnerability-in-a-3-million-downloads-week-npm-package-19089.md>)

Original publisher: [Read original article](<https://httptoolkit.com/blog/npm-pac-proxy-agent-vulnerability/>)

Author: HTTP Toolkit; Tim Perry

Published: 2021-08-31T11:00:00Z

Content type: article

Language: en

Sources: [HTTP Toolkit](<https://devfeed.tech/sources/http-toolkit.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Network](<https://devfeed.tech/topics/network.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Firebase](<https://devfeed.tech/topics/firebase.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [cli](<https://devfeed.tech/tags/cli.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [firebase](<https://devfeed.tech/tags/firebase.md>), [firebase-cli](<https://devfeed.tech/tags/firebase-cli.md>), [github](<https://devfeed.tech/tags/github.md>), [http](<https://devfeed.tech/tags/http.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [network](<https://devfeed.tech/tags/network.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [npm](<https://devfeed.tech/tags/npm.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [remote-code-execution-vulnerability](<https://devfeed.tech/tags/remote-code-execution-vulnerability.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article examines CVE-2021-23406, a high-severity remote code execution vulnerability in the Pac-Resolver NPM dependency. The issue can affect Node.js applications using untrusted PAC or proxy configuration, and was fixed in Pac-Resolver v5.0.0 and related packages.

### Source excerpt

Pac-Resolver, a widely used NPM dependency, had a high-severity RCE (Remote Code Execution) vulnerability that could allow network administrators or other malicious actors on your local network to remotely run arbitrary code inside your Node.js process whenever you tried to send an HTTP request. This is bad! This package is used for PAC file support in Pac-Proxy-Agent, which is used in turn in Proxy-Agent, which then used all over the place as the standard go-to package for HTTP proxy autodetection & configuration in Node.js. It's very popular: Proxy-Agent is used everywhere from AWS's CDK toolkit to the Mailgun SDK to the Firebase CLI (3 million downloads per week in total, and 285k public dependent repos on GitHub). I found this lovely little issue a short while back, while adding proxy support to HTTP Toolkit (yes, code reviewing your dependencies is a good idea!). The vulnerability was fixed in v5.0.0 of all those packages recently, and was formally disclosed last week as CVE-2021-23406. First things first: are you personally at risk? This vulnerability seriously affects you if: You depend on Pac-Resolver before v5.0.0 (even transitively) in a Node.js application And, you do one of the below: Explicitly use PAC files for proxy configuration. Read & use the operating system proxy configuration in Node.js, on systems with WPAD enabled. Use proxy configuration (env vars, config files, remote config endpoints, command-line arguments) from any other source that you wouldn't 100% trust to freely run code on your computer. In any of those cases, an attacker (by configuring a malicious PAC URL, intercepting PAC file requests with a malicious file, or using WPAD) can remotely run arbitrary code on your computer any time you send an HTTP request using this proxy configuration. If you're in this situation, you need to update (to Pac-Resolver v5 and/or Proxy-Agent v5) right now. If not, you're probably not in any immediate risk (but it's a good idea to update anyway). For n

[Next page](<https://devfeed.tech/tags/remote-code-execution.md?cursor=WyIyMDIxLTA4LTMxVDExOjAwOjAwKzAwOjAwIiwgImZkZTM2OGI5LWEwM2EtNDUxMS1hYzUyLTRiZTNiYzdlYmRlMSJd>)