Server-side request forgery: the redirect that walks past your allowlist
Server-side request forgery: the redirect that walks past your allowlist What...
Tag archive
Server-side request forgery: the redirect that walks past your allowlist What...
How the instance metadata service turns a server-side request forgery into cloud credentials, and how to reduce it.

How to fix CVE-2026-94483: upgrade next to 15.5.27 or 16.3.8
How the SonicWall SMA1000 SSRF and command-injection chain shows why edge appliance patch windows and management-plane exposure matter more than vendor-wide asset counts.

Originally published at trustboundarystudio.com. The video version, with diagrams, is on YouTube. ...
Technical analysis of CVE-2026-12944 in IBM Langflow OSS: how an incomplete scanner blocklist enables authenticated code execution, plus affected versions, exposure data and remediation.
MISP Feed Redirects Before 2.5.45: When an Outbound Request Carries Credentials to Another...
Choosing a Mature Library Over Custom Security Code Last week I submitted a PR to...
SSRF in PyTorch: How a Missing URL Validation Could Leak Cloud Credentials What...
An unauthenticated SSRF flaw in MLflow (CVE-2026-64849) is being actively exploited to steal cloud credentials and secrets from mis‑configured deployments. Patch now to protect your AI pipelines.

CVE-2026-75885 fixes are available for OpenShift 4.19.49, 4.20.40, 4.21.35, and 4.22.16.
I found a security flaw in IBM's Langflow and CrewAI that lets attackers reach internal networks....