Disclosures
Vulnerability disclosures
Security research, responsibly disclosed. Public CVEs discovered by Cantina's autonomous AppSec agents, human-verified, and coordinated with the affected vendors.
cantina · disclosures
24 published- Agent discovery done
- Human verification done
- Vendor coordination done
- CVE published in progress
Every CVE is agent-found, human-verified, and coordinated with the vendor before it's public.
Found by agents. Verified by humans. Disclosed by the book
Every CVE below started as an exploit path an autonomous agent proved, then became a human-verified finding coordinated with the vendor.
- Verified CVEs, publicly disclosed
- 0 Verified CVEs, publicly disclosed
- New findings in the latest batch
- 0 New findings in the latest batch
- Projects & products affected
- 0 Projects & products affected
- Agent-found, then human-verified
- 0% Agent-found, then human-verified
- Critical
- 2
- High
- 11
- Medium
- 10
- Low
- 1
Every finding, in the open
Each entry was surfaced by an autonomous AppSec agent, confirmed by our research team, and coordinated with the vendor before going public.
- Agent discovery
- Human verified
- Responsibly disclosed
Showing 24 of 24
OAuth consumers retain access after token expiry
Topic permissions fail open during metadata errors
Proxy handling bypasses loopback-only authentication
Direct-reply-to bindings enable cross-tenant injection
Embedded NUL bytes can silently rebind TLS authority
Mixed-case SNI can bypass mTLS trust policies
Unicode hostname separators bypass TLS wildcard depth
Temporary session tokens can bypass two-factor authentication
Malicious registry crates can overwrite dependency source
DNS timing race can trigger a use-after-free
Cross-origin redirects can forward sensitive headers
Thirteen-year WebKit flaw bypasses Content Security Policy
WebKit data-protection flaw exposes sensitive user data
WebKit input validation bypasses Content Security Policy
Cached public pages can expose user sessions
Servlet-path matching can deactivate security controls
ECH server-name handling writes beyond allocated memory
Forged admin forms can create unauthorized model instances
Empty-index decoding can trigger heap buffer overflow
Short X-Wing keys trigger an out-of-bounds read
Filter keys enable Cypher injection in Neo4j stores
User-controlled filter keys enable SpEL code execution
Repository settings can skip the workspace trust prompt
Command mismatch can bypass execution approval
New CVE IDs are reserved with the affected vendor while a fix is coordinated; full technical detail publishes once users can patch.
See what Apex finds in your environment
The same autonomous AppSec agents behind these CVEs can move you from exploit path to a human-verified finding your team can act on.