moltenbit

I look for security bugs and publish them once they are fixed.

One column per disclosure, oldest on the left.

46 disclosures 40 CVEs since 2026-03 latest 2026-09-29

  • 7 critical
  • 13 high
  • 19 moderate
  • 6 low
  • 1 no score

Writeups

all writeups

Recent disclosures

all 46
OpenSSL

QUIC stack enforces the stream-level but not the connection-level flow control limit, letting a remote peer make one connection allocate about 100 MB of heap instead of the 768 KiB window

CVE-2026-10627
Events Manager WordPress Plugin

missing authorization lets unauthenticated attackers use status, private, and private_only parameters to view draft, pending, trashed, or private event and location details

CVE-2026-71540
Wazuh

pre-authentication cluster header parsing lets one source IP allocate 256 MiB of manager memory per TCP connection

CVE-2026-74046
Wazuh

zlib decompression bomb in cluster archive processing lets an authenticated peer exhaust wazuh-clusterd memory

CVE-2026-74044
Wazuh

peer-controlled cluster hello node name lets an authenticated peer delete the contents of arbitrary manager directories on disconnect