Latest articles

Application security blog

CVE explainers, code review patterns and practical guidance for people who build and own software.

  1. CVE explainers

    After React2Shell: three security boundaries every server component review needs

    A technical review method for React2Shell and CVE-2026-23864: separate safe decoding, permission checks and bounded work, then verify the deployed build.

    Read article
  2. Security news

    The 2026 Axios attack: why a clean dependency tree cannot clear a build runner

    An evidence-led analysis of the Axios supply-chain compromise: trace package installation, code execution and credential reach before declaring recovery complete.

    Read article
  3. CVE explainers

    CVE-2024-26855: when a missing attribute becomes a NULL dereference

    A Linux ice driver fix illustrates a common review mistake: treating a parser’s optional result as a guaranteed object.

    Read article
  4. CVE explainers

    CVE-2025-37858: a 64-bit destination cannot fix a narrow shift

    A JFS allocation-group calculation demonstrates why code review must inspect the width of an operation before its result is assigned.

    Read article
  5. Practical guides

    Security code review or penetration testing: what should you buy?

    Choose the engagement from the question your product team needs answered, the access available and the change you need to make.

    Read article