Lab_01 // Research & Disclosures
Vulnerability research and CVE disclosures.
Bugs found in software other people ship, and the writeups on how they work.
Assigned CVEs
7
Research Writeups
1
Last Published
Feb 2026
01 // Disclosures
Each one has a CVE and a vendor advisory.
IdentifierAdvisoryAffected productPublished
CVE-2026-25537Type Confusion leads to potential authorization bypassjsonwebtoken (rust)Feb 3, 2026CVE-2025-61582Unauthenticated denial of service leading to application crash in Ts3 manager <=v2.2.1TS3 managerOct 1, 2025CVE-2025-61583Unauthenticated reflected cross-site scripting in `Server` parameter in Ts3 manager <=v2.2.1TS3 managerOct 1, 2025CVE-2025-54123Remote Code Execution in Hoverfly Middleware API (/api/v2/hoverfly/middleware)HoverflySep 11, 2025CVE-2025-54376Unauthenticated Access to Admin WebSocket Log Streaming Endpoint in HoverflyHoverflySep 11, 202502 // Research
Longer writeups on how a bug works. Commentary and guides go on the blog.
03 // Tooling
Working with us
The same research approach is available as an engagement. If one of these bug classes applies to something you run, we can look at your environment directly.