CVE-2024-24791 - Exploiting Go net/http "Expect: 100-continue" Client Handling for DoS
Go’s net/http package is a cornerstone for many web applications and services, powering everything from simple HTTP servers to robust reverse proxies. But
CVE-2024-39891 - Exposed Authy Phone Number Lookup — How Twilio’s API Leaked User Data
In June 2024, security researchers spotted a worrying flaw in the Twilio Authy API—used by millions for secure two-factor authentication. This vulnerability, logged
CVE-2024-34122 - Out-of-Bounds Read Vulnerability in Acrobat for Edge Exposes Users to Remote Code Execution
Summary:
Recently, a serious vulnerability, CVE-2024-34122, was discovered in Adobe Acrobat’s Edge browser extension (versions 126..2592.68 and earlier). This out-
CVE-2024-38366 - Remote Code Execution Vulnerability in trunk.cocoapods.org via MX Lookup
A critical vulnerability (CVE-2024-38366) in the trunk.cocoapods.org, the authentication server behind the CocoaPods package manager, exposed the entire infrastructure to Remote
CVE-2024-39573 - How An SSRF in Apache mod_rewrite Can Lead to a Proxy Disaster
Apache HTTP Server is one of the most popular web servers on the planet. But even giants can have weak spots. If you’re running
Episode
00:00:00
00:00:00