The catalog
Browse Reproductions
276 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
276 reproductions
REPRO-2026-00148 published
Mistune: ReDoS via catastrophic backtracking in LINK_TITLE_RE
CVE-2026-33079 high Security
Variant found
pip
mistune
14m 50s May 22, 2026
REPRO-2026-00147 published
Faraday: SSRF via protocol-relative URL overriding base authority
CVE-2026-25765 medium Security
Variant found
rubygems
faraday
10m 15s May 22, 2026
REPRO-2026-00146 published
fast-uri: host confusion via percent-encoded authority delimiter in normalize()
CVE-2026-6322 high Security
Variant found
npm
fast-uri
10m 18s May 22, 2026
REPRO-2026-00145 published
fast-uri: path traversal via percent-encoded segments decoded before normalization
CVE-2026-6321 high Security
Variant found
npm
fast-uri
10m 8s May 22, 2026
REPRO-2026-00144 published
phpMyFAQ: unauthenticated SQL injection via User-Agent header in captcha API
CVE-2026-46364 critical Security
Variant found
composer
thorsten/phpmyfaq
62m 14s May 22, 2026
REPRO-2026-00143 published
@wdio/browserstack-service: OS command injection via crafted git branch name
CVE-2026-25244 critical Security
Variant found
npm
@wdio/browserstack-service
59m 49s May 22, 2026
REPRO-2026-00142 published
libheif: integer underflow out-of-bounds read crash via crafted HEIF stsc box
CVE-2026-32738 medium Security
Variant found
c
libheif
50m 30s May 22, 2026
REPRO-2026-00141 published
rsync: off-by-one out-of-bounds stack write in establish_proxy_connection
CVE-2026-45232 low Security
Variant found
c
rsync
29m 29s May 22, 2026
REPRO-2026-00140 published
zenshin: OS command injection in /stream-to-vlc url query parameter
CVE-2026-37281 critical Security
Variant found
zenshin
28m 3s May 22, 2026
REPRO-2026-00139 published
libjwt: JWT algorithm-confusion authentication bypass via RSA JWK without alg
CVE-2026-44699 critical Security
Variant found
c
libjwt
13m 26s May 22, 2026
REPRO-2026-00138 published
FastMCP: path traversal to authenticated SSRF in OpenAPIProvider _build_url()
CVE-2026-32871 critical Security
Variant found
pip
fastmcp
37m 15s May 22, 2026
REPRO-2026-00137 published
ExifReader: unbounded memory amplification DoS via crafted ICC mluc tag
CVE-2026-8813 high Security
Variant found
npm
exifreader
35m 45s May 22, 2026
REPRO-2026-00136 published
Microsoft APM: arbitrary file disclosure via symlink-following on apm install
CVE-2026-45539 high Security
Variant found
pip
apm
29m 1s May 22, 2026
REPRO-2026-00135 published
jsondiffpatch: prototype pollution via crafted delta in patch()
CVE-2026-8657 high Security
Variant found
npm
jsondiffpatch
23m 26s May 22, 2026
REPRO-2026-00134 published
lodash: prototype pollution in _.unset/_.omit deletes global prototype methods
CVE-2025-13465 medium Security
Variant found
npm
lodash
29m 27s May 22, 2026
REPRO-2026-00133 published
Drupal core: unauthenticated SQL injection via JSON:API filter array keys
CVE-2026-9082 critical Security
Variant found
composer
drupal/core
21m 27s May 22, 2026
REPRO-2026-00132 published
ShowDoc Unauthenticated File Upload RCE via deprecated ThinkPHP syntax
CVE-2025-0520 critical Security
Variant found
github
showdoc/showdoc
139m 41s Apr 14, 2026
REPRO-2026-00131 published
Apache Tomcat EncryptInterceptor Bypass via CVE-2026-29146 Fix Error - Missing Encryption of Sensitive Data
CVE-2026-34486 high Security
Variant found
Apache Tomcat
19m 38s Apr 14, 2026
REPRO-2026-00130 published
pymetasploit3 command injection
CVE-2026-5463 high Security
Variant found
PyPI
DanMcInerney/pymetasploit3
36m 8s Apr 4, 2026
REPRO-2026-00129 published
Go MCP SDK DNS Rebinding - Server-Side Request Forgery on AI Infrastructure
CVE-2026-34742 high Security
Variant found
Go module
github.com/modelcontextprotocol/go-sdk
38m 55s Apr 4, 2026