⤷ Title: JWT attacks
════════════════════════
𐀪 Author: Zodiac Hacker
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 14:58:29 GMT
════════════════════════
⌗ Tags: #vulnerability #server_side #web #ssrf #hacking
════════════════════════
𐀪 Author: Zodiac Hacker
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 14:58:29 GMT
════════════════════════
⌗ Tags: #vulnerability #server_side #web #ssrf #hacking
Medium
JWT attacks
How it normally works vs How jwt works (nothing saved in server).
⤷ Title: API7:2023 — Server-Side Request Forgery: API’yi İç Sistemlere Köprü Olarak Kullanmak
════════════════════════
𐀪 Author: Apifort
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 04:16:27 GMT
════════════════════════
⌗ Tags: #server_side_request #apifort #owasp_api_security_top_10 #cybersecurity #ssrf
════════════════════════
𐀪 Author: Apifort
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 04:16:27 GMT
════════════════════════
⌗ Tags: #server_side_request #apifort #owasp_api_security_top_10 #cybersecurity #ssrf
Medium
🚨API7:2023 — Server-Side Request Forgery: API’yi İç Sistemlere Köprü Olarak Kullanmak
1. Giriş
⤷ Title: Understanding SQL Injection: Basics, Types, and How to Prevent It
════════════════════════
𐀪 Author: HackLog
════════════════════════
ⴵ Time: Sat, 06 Sep 2025 13:24:20 GMT
════════════════════════
⌗ Tags: #server_side_security #sql_injection #example #mitigation #types_of_sql_injection
════════════════════════
𐀪 Author: HackLog
════════════════════════
ⴵ Time: Sat, 06 Sep 2025 13:24:20 GMT
════════════════════════
⌗ Tags: #server_side_security #sql_injection #example #mitigation #types_of_sql_injection
Medium
Understanding SQL Injection: Basics, Types, and How to Prevent It
Hey everyone!
⤷ Title: TryHackMe Walkthrough: Include
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 02:44:57 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #web_application_hacking #ethical_hacking #include_thm_writeup #server_side_vulnerability
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 02:44:57 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #web_application_hacking #ethical_hacking #include_thm_writeup #server_side_vulnerability
Medium
TryHackMe Walkthrough: Include
Use your server exploitation skills to take control of a web app (Link to TryHackMe room here)
⤷ Title: CVE-2025-61927 (CVSS 9.4): Critical RCE Flaw Discovered in Happy DOM, Over 2.7 Million Weekly Downloads Impacted
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:00:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_61927 #Happy DOM #Node.js #rce #Server_Side Rendering #VM Escape
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:00:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_61927 #Happy DOM #Node.js #rce #Server_Side Rendering #VM Escape
Daily CyberSecurity
CVE-2025-61927 (CVSS 9.4): Critical RCE Flaw Discovered in Happy DOM, Over 2.7 Million Weekly Downloads Impacted
A Critical (CVSS 9.4) flaw in Happy DOM allows untrusted JavaScript to escape the Node.js VM context and achieve RCE on the host system via the Function inheritance chain.
⤷ Title: Zimbra Issues Emergency Patch for Critical SSRF Vulnerability in Chat Proxy Configuration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 08:54:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Chat Proxy #cybersecurity #Server_Side Request Forgery #ssrf #Zimbra #Zimbra 10.1.x
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 08:54:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Chat Proxy #cybersecurity #Server_Side Request Forgery #ssrf #Zimbra #Zimbra 10.1.x
⤷ Title: Lab 1: Basic server-side template injection (Server-side template injection)
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 12:23:43 GMT
════════════════════════
⌗ Tags: #server_side_injection #server_side_template #burpsuite #portswigger_lab #ssrf
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 12:23:43 GMT
════════════════════════
⌗ Tags: #server_side_injection #server_side_template #burpsuite #portswigger_lab #ssrf
Medium
Lab 1: Basic server-side template injection (Server-side template injection)
This lab is vulnerable to server-side template injection due to the unsafe construction of an ERB template.
⤷ Title: Critical React Router Flaws: CVE-2025-61686 Exposes Server Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 02:32:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_61686 #React Router #Remix Framework #Server_Side Rendering (SSR) #Session Hijacking #Web Security #XSS (Cross_Site Scripting)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 02:32:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_61686 #React Router #Remix Framework #Server_Side Rendering (SSR) #Session Hijacking #Web Security #XSS (Cross_Site Scripting)
Daily CyberSecurity
Critical React Router Flaws: CVE-2025-61686 Exposes Server Files
Developers relying on the popular React Router library are being urged to patch their applications immediately following the disclosure of multiple high-severity vulnerabilities. The flaws, rangin…
⤷ Title: CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:21:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_25526 #ForTag Vulnerability #HubSpot CMS #Java Template Engine #Jinjava #ObjectMapper Deserialization #Patch Alert #Remote Code Execution #Sandbox Escape #Server Side Template Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:21:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_25526 #ForTag Vulnerability #HubSpot CMS #Java Template Engine #Jinjava #ObjectMapper Deserialization #Patch Alert #Remote Code Execution #Sandbox Escape #Server Side Template Injection
Daily CyberSecurity
CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution
Critical Jinjava flaw CVE-2026-25526 (CVSS 9.8) breaks sandbox security. Attackers can execute Java code via template loops. Update to v2.8.3 now.
⤷ Title: Steering the Server: Critical 9.2 Severity SSRF Flaw in Angular SSR Allows Internal Network Probing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:14:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #CVE_2026_27739 #Frontend Security #HttpClient #infosec #Patch Alert #Server_Side Request Forgery #SSR #ssrf #Vulnerability #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:14:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #CVE_2026_27739 #Frontend Security #HttpClient #infosec #Patch Alert #Server_Side Request Forgery #SSR #ssrf #Vulnerability #Web Security
Daily CyberSecurity
Steering the Server: Critical 9.2 Severity SSRF Flaw in Angular SSR Allows Internal Network Probing
Angular patches a critical 9.2 CVSS SSRF vulnerability (CVE-2026-27739). Attackers can manipulate Host headers to steal credentials and probe internal networks.
⤷ Title: High-Severity SSRF Flaw Uncovered in Angular’s Server-Side Rendering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:32:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@angular/platform_server #Angular #CVE #infosec #javascript #Origin Hijacking #Server_Side Rendering #SSR #ssrf #TypeScript #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:32:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@angular/platform_server #Angular #CVE #infosec #javascript #Origin Hijacking #Server_Side Rendering #SSR #ssrf #TypeScript #Web Security
Daily CyberSecurity
High-Severity SSRF Flaw Uncovered in Angular’s Server-Side Rendering
Angular patches a critical 8.7 SSRF flaw in @angular/platform-server. Attackers can hijack SSR origins via URL normalization. Patch v19, v20, or v21 now!
⤷ Title: Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
Daily CyberSecurity
Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
Thymeleaf 3.1.4 fixes two critical 9.1 CVSS vulnerabilities. Unauthenticated attackers can bypass security for SSTI. Audit your user input and patch today!
⤷ Title: CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
Daily CyberSecurity
CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
CVE-2026-33626: A critical SSRF in LMDeploy exploited in under 13 hours. Learn how attackers hijack AI nodes and how to secure your inference cloud now.
⤷ Title: GitOps Security Breach: Critical 9.6 CVSS Argo CD Flaw Exposes Plaintext Kubernetes Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 02:02:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Argo CD #cloud_native #CVE_2026_42880 #cybersecurity #data leak #GitOps #infosec #Kubernetes #Kubernetes Secrets #Patch Alert #Server_Side Diff
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 02:02:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Argo CD #cloud_native #CVE_2026_42880 #cybersecurity #data leak #GitOps #infosec #Kubernetes #Kubernetes Secrets #Patch Alert #Server_Side Diff
Daily CyberSecurity
GitOps Security Breach: Critical 9.6 CVSS Argo CD Flaw Exposes Plaintext Kubernetes Secrets
A critical 9.6 CVSS flaw in Argo CD (CVE-2026-42880) allows read-only users to extract plaintext Kubernetes secrets via Server-Side Diffs. Patch to v3.3.9 now!
⤷ Title: Critical 9.0 CVSS Flaw in Thymeleaf Enables Remote Server Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 12:38:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_41901 #cybersecurity #infosec #Java security #Patch Alert #rce #Sandbox Bypass #Server Side Template Injection #ssti #Thymeleaf #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 12:38:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_41901 #cybersecurity #infosec #Java security #Patch Alert #rce #Sandbox Bypass #Server Side Template Injection #ssti #Thymeleaf #web development
Daily CyberSecurity
Critical 9.0 CVSS Flaw in Thymeleaf Enables Remote Server Injection
Critical 9.0 CVSS flaw in Thymeleaf (CVE-2026-41901) allows SSTI and arbitrary code execution. Secure your Java web apps—upgrade to v3.1.5.RELEASE now!
⤷ Title: Open Proxy Risk: High-Severity Next.js SSRF Flaw Exposes Cloud Metadata Endpoints
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 06:56:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cloud Metadata Exploit #CVE_2026_44578 #CWE_918 #Next.js #Security Patch 2026 #Self_Hosted Node.js #Server_Side Request Forgery #SSRF #Vercel #WebSocket Upgrade
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 06:56:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cloud Metadata Exploit #CVE_2026_44578 #CWE_918 #Next.js #Security Patch 2026 #Self_Hosted Node.js #Server_Side Request Forgery #SSRF #Vercel #WebSocket Upgrade
Penetration Testing Tools
Open Proxy Risk: High-Severity Next.js SSRF Flaw Exposes Cloud Metadata Endpoints
The development framework Next.js has remediated a critical security vulnerability, designated as CVE-2026-44578, which afflicts applications deployed on
⤷ Title: Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 01:01:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache OFBiz #Authentication Bypass #CVE_2026_31378 #CVE_2026_45434 #Cyber Security #infosec #JSON Attribute Manipulation #Patch Alert #Remote Code Execution #Server Side Template Injection #ssti
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 01:01:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache OFBiz #Authentication Bypass #CVE_2026_31378 #CVE_2026_45434 #Cyber Security #infosec #JSON Attribute Manipulation #Patch Alert #Remote Code Execution #Server Side Template Injection #ssti
Daily CyberSecurity
Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
Apache OFBiz releases version 24.09.06 to patch severe RCE flaws, token forgery, and a critical password-reset authentication bypass. Upgrade now!
⤷ Title: Automated Remediation: Microsoft Resolves Cumulative Update Rollback Failures
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 12:24:13 +0000
════════════════════════
⌗ Tags: #Windows #component store corruption #DISM manual fix tool #installation loops error #server side rollback #update installation fault #Windows 11 update anomaly
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 12:24:13 +0000
════════════════════════
⌗ Tags: #Windows #component store corruption #DISM manual fix tool #installation loops error #server side rollback #update installation fault #Windows 11 update anomaly
Daily CyberSecurity
Automated Remediation: Microsoft Resolves Cumulative Update Rollback Failures
Discover how to resolve the Windows 11 update anomaly. Learn how Microsoft updates trigger installation loops and how to fix them using manual DISM tools.
⤷ Title: Cloudflare Workers Cache: Edge Caching for Workers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 03:19:32 +0000
════════════════════════
⌗ Tags: #Technology #Cache_Tag #cloudflare #Cloudflare Workers #Edge Caching #Server_Side Rendering #web performance #Workers Cache
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 03:19:32 +0000
════════════════════════
⌗ Tags: #Technology #Cache_Tag #cloudflare #Cloudflare Workers #Edge Caching #Server_Side Rendering #web performance #Workers Cache
Daily CyberSecurity
Cloudflare Workers Cache: Edge Caching for Workers
Cloudflare has launched Workers Cache, a dedicated frontend caching layer built specifically for Cloudflare Workers. With this release, Workers can act as their own origin. They can now also benef…
⤷ Title: CVE-2026-15378: Blind SSRF Flaw in Red Hat OpenShift AI
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 15:00:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_15378 #Kubernetes #OpenShift AI #red hat #Red Hat OpenShift AI #Server_Side Request Forgery #ssrf
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 15:00:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_15378 #Kubernetes #OpenShift AI #red hat #Red Hat OpenShift AI #Server_Side Request Forgery #ssrf
Daily CyberSecurity
CVE-2026-15378: Blind SSRF Flaw in Red Hat OpenShift AI
TL;DR Red Hat has flagged a critical flaw in Red Hat OpenShift AI. Tracked as CVE-2026-15378, it scores 9.3 on CVSS. The bug lets a remote attacker run a blind SSRF and read local files. No exploi…