runtz
    Playground
  • Pricing
  • AI
  • Docs
  • Newsletter
    Login

Newsletter

DevSecOps
All articlesAppSec1company1DevSecOps3host1

By subscribing, you agree to receive our newsletter. Privacy policy.

Latest articles

03 / articles
SCA Deep Dive #1 — Axios (CVE-2025-27152) - Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URLSCA Deep Dive #1 — Axios (CVE-2025-27152) - Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
AppSec5 min

SCA Deep Dive #1 — Axios (CVE-2025-27152) - Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL

Axios can ignore baseURL when the path is already an absolute URL. The request goes elsewhere and the default headers can go with it.

Sep 28, 2026
Cover for Host Deep Dive #1 with the title "Copy Fail", a blue terminal cursor and the identifier CVE-2026-31431.Cover for Host Deep Dive #1 with the title "Copy Fail", a blue terminal cursor and the identifier CVE-2026-31431.
host7 min

Host Deep Dive #1 — Copy Fail (CVE-2026-31431): how a kernel copy bug can lead to root

CVE-2026-31431 affects the Linux kernel's AF_ALG crypto socket interface. An unprivileged process can modify the page cache, causing other processes to read file contents that differ from what's on disk.

Sep 22, 2026
Cover with the title "Why We're Building runtz" in monospace type, followed by a blue terminal cursor.Cover with the title "Why We're Building runtz" in monospace type, followed by a blue terminal cursor.
company1 min

Why We're Building runtz

Security scanning should be simpler.

Sep 22, 2026