Published onJune 3, 2026HTTP/2 Bomb: Denial-of-Service Exploit Against Major Web Serverssecurity-bulletinAddressing CVE-2026-49975, a denial-of-service exploit against most major web servers, including: nginx, Apache httpd, Microsoft IIS, Envoy, etc.
Published onDecember 3, 2025React2Shell: Remote Code Execution in React Server Componentssecurity-bulletinAddressing React2Shell CVE-2025-55182 (React) & CVE-2025-66478 (NextJS) Remote Code Execution (RCE) in React Server Components
Published onMarch 23, 2025CVE-2025-29927: Authorization Bypass in NextJS Middlewaresecurity-bulletinAddressing CVE-2025-29927 Authorization Bypass in NextJS Middleware