vulns.co
/
GKData.io MCP

126 records / Open collection

Reading room.

Standards, maintainer advisories, research papers, and practical learning from primary sources.

126 matching records

arXiv Research Paper

Web cache key precision and capacity isolation

This author-submitted study connects unnecessary cache-key variation with redundant object storage, reduced cache effectiveness and increased origin load. It treats cache-key design as an application availability…

Reviewed 2026-10-03Read

Amazon Web Services Implementation Guide

AWS IAM security best practices for workload identities

Use this guide to review machine identity design: favor short-lived role credentials for workloads, limit permissions to required actions and resources, and retire unnecessary access. It also explains policy validation,…

Reviewed 2026-10-02Read

Google Chrome for Developers Implementation Guide

Chrome bfcache: restored pages and session-state boundaries

Explains Chrome’s conditional admission of no-store pages to the back/forward cache. A restored page resumes in-memory document state rather than performing a fresh network load. The guide describes eviction safeguards…

Reviewed 2026-10-03Read

Django Software Foundation Maintainer Advisory

Django: ORM alias metadata must not acquire query authority

Django confirms CVE-2026-1312: application-controlled column aliases could cross from metadata into SQL structure when used across relation filtering and ordering. Exploitability requires an application to admit…

Reviewed 2026-10-03Read

GitHub Security Lab Research Paper

GraphQL-Ruby: authorization exceptions must stop execution

A GraphQL-Ruby execution-engine path converted a resolver authorization exception into permission to continue. Research demonstrates a denied resolver running and returning a fixture value, while the legacy engine…

Reviewed 2026-10-03Read

HackerOne Help Center Reporting Guide

Quality Reports

Official guidance for concise security reports: clear titles, expected versus actual behavior, evidence-backed impact, useful supporting material, scope checks, and remediation suggestions.

Reviewed 2026-10-02Read

Model Context Protocol Technical Standard

MCP elicitation: consent, credential custody and completion

Form elicitation excludes secrets. URL elicitation places sensitive interactions outside the MCP client and model context, with the requesting server and destination visible to the user. Agreeing to open the interaction…

Reviewed 2026-10-04Read

National Institute of Standards and Technology Architecture Guide

NIST SP 800-162: attribute authority and policy traceability

Defines authorization in terms of subject, object, operation and environmental attributes evaluated against policy. Enterprise considerations connect business rules to machine-enforced decisions, attribute authorities…

Reviewed 2026-10-03Read

National Institute of Standards and Technology Architecture Guide

NIST SP 800-190: Application Container Security Guide

A foundational model of container images, registries, orchestration, runtimes and host security. It explains shared-kernel risk, workload separation, constrained runtime permissions and lifecycle maintenance.

Reviewed 2026-10-02Read

OpenID Foundation Technical Standard

FAPI 2.0 Security Profile

Defines a high-security OAuth profile with coordinated requirements for confidential clients, authorization servers, and resource servers. Connects sender-constrained tokens and authorization-request integrity with the…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Forgot Password

Explains account-bound recovery challenges, limited lifetime and reuse, consistent responses, attempt controls, notifications and post-reset session handling.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

Authorization Cheat Sheet

Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

HTML5 Security Cheat Sheet: Web Messaging

OWASP explains origin checks, expected message formats and treating exchanged content as data. These controls address different assumptions at browser communication boundaries.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

Error Handling Cheat Sheet

OWASP guidance on centralized handling of unexpected failures, generic client-facing responses and server-side diagnostic records that do not reveal implementation details to clients.

Reviewed 2026-10-02Read

OWASP Gen AI Security Project Implementation Guide

OWASP LLM05:2025: generated-output consumer trust

Explains why model-generated content remains untrusted when passed to browsers, databases or backend functions. The relevant boundary is the consuming component: plausible model text must not acquire executable meaning…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Architecture Guide

LLM Prompt Injection Prevention Cheat Sheet

Defense-in-depth guidance for LLM applications that consume untrusted content or invoke tools. Covers data provenance, least privilege, action authorization, monitoring, and the limitations of guardrails.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Secure Code Review: baseline and change-focused review

Explains how whole-codebase reviews and change-focused reviews answer different assurance questions. Connects architecture, business requirements and existing findings to manual examination of data movement, control…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Logging: trustworthy and minimal application evidence

Explains how application events support investigation through consistent context, interaction identifiers, outcomes and confidence information. Distinguishes event occurrence from recording time and treats…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Server-Side Request Forgery Prevention

Explains destination validation and network isolation for server-initiated requests, distinguishing fixed trusted destinations from services that need broader external access.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Session Management: privilege-transition integrity

Distinguishes application-issued session identifiers from client-selected values. Explains renewing identifiers at login and other privilege changes, retiring previous identifiers, and separating anonymous tracking from…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Transaction Authorization

Explains operation-specific approval: show significant transaction details, preserve authorized data, enforce valid state transitions and recheck authorization at execution.

Reviewed 2026-10-02Read

jhb-software / Payload plugins Maintainer Advisory

Payload: request adapters must retain caller-level authorization

CVE-2026-59965 describes authenticated plugin endpoints invoking a privileged server interface without preserving collection-level authorization. Payload's Local API skips access checks by default, so a session check…

Reviewed 2026-10-04Read

PortSwigger Research Paper

Upstream HTTP framing and parser-consistency boundaries

The researcher explains how inconsistent message-boundary interpretation across proxies and origins can break request isolation on shared upstream connections. Client-facing HTTP/2 alone does not remove this risk when…

Reviewed 2026-10-03Read

PostgreSQL Global Development Group Implementation Guide

PostgreSQL 18: Transaction Isolation and Business Invariants

Explains why a stable database snapshot alone does not preserve business rules across concurrent transactions. PostgreSQL distinguishes serializable consistency from explicit locking and requires serialization-failure…

Reviewed 2026-10-03Read

Prowler Maintainer Advisory

Prowler SAML: retain validated tenant authority

CVE-2026-59151 concerns token issuance selecting a tenant from an asserted email domain instead of retaining the validated SAML configuration. Maintainers describe potential cross-tenant account takeover. Their…

Reviewed 2026-10-03Read

Internet Engineering Task Force / RFC Editor Technical Standard

RFC 10017: OAuth 2.0 for Browser-Based Applications

Compares browser-only OAuth clients, token-mediating backends, and backend-for-frontend architectures through their different token-custody and session boundaries. Separates protection of token material from the…

Reviewed 2026-10-03Read

Internet Engineering Task Force / RFC Editor Technical Standard

RFC 9700: Best Current Practice for OAuth 2.0 Security

Consensus guidance updating OAuth's security model with deployment experience, stronger protocol requirements, and deprecated insecure patterns. A primary reference for identity integration reviews.

Reviewed 2026-10-02Read

samlify Maintainer Advisory

samlify: signing does not establish claim provenance

The maintainer describes inconsistent escaping between XML attribute and element-text contexts during SAML assertion generation. User-controlled profile values could change assertion structure before the identity…

Reviewed 2026-10-03Read

SLSA Community Security Standard

SLSA v1.2: supply-chain security and build provenance

Learn to assess software supply-chain assurance using distinct source and build tracks. The build track progresses from recording provenance to authenticated hosted builds and stronger platform isolation. Build…

Reviewed 2026-10-02Read

GitHub Security Lab Research Paper

Spree: guest ownership still requires an authorization proof

CVE-2026-25757 concerns completed guest orders. The access decision treated absence of an account owner as sufficient permission, while lookup did not require the separate order token. GHSL identifies the flaw in tested…

Reviewed 2026-10-03Read

World Wide Web Consortium Technical Standard

Fetch Metadata Request Headers

Defines browser-provided request context covering site relationship, destination, mode, and user activation. Explains how redirect history affects that context and why context-dependent responses need matching cache…

Reviewed 2026-10-03Read

WHATWG Technical Standard

HTML COOP: opener separation and same-origin authority

Defines how opener policies affect browsing-context separation during navigation. The standard expressly distinguishes severing an opener relationship from a robust boundary between same-origin documents: storage,…

Reviewed 2026-10-03Read

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software