moltenbit

I break software before someone worse does.

Security research and bug bounty, done the boring way: reported to the vendor, fixed, then written up here.

Latest writeups / 3

all writeups →

From the ledger / 5 of 45

full ledger →
CVE-2026-10627
Events Manager WordPress Plugin

missing authorization lets unauthenticated attackers use status, private, and private_only parameters to view draft, pending, trashed, or private event and location details

CVE-2026-71540
Wazuh

pre-authentication cluster header parsing lets one source IP allocate 256 MiB of manager memory per TCP connection

CVE-2026-74046
Wazuh

zlib decompression bomb in cluster archive processing lets an authenticated peer exhaust wazuh-clusterd memory

CVE-2026-74044
Wazuh

peer-controlled cluster hello node name lets an authenticated peer delete the contents of arbitrary manager directories on disconnect

CVE-2026-48024
Wazuh

merged-file header path traversal in cluster sync allows a cluster peer to write arbitrary files under WAZUH_PATH and reach root code execution