Latest articles

Application security blog

CVE explainers, code review patterns and practical guidance for people who build and own software.

  1. CVE explainers

    After React2Shell: three security boundaries every server component review needs

    A technical review method for React2Shell and CVE-2026-23864: separate safe decoding, permission checks and bounded work, then verify the deployed build.

    Read article
  2. CVE explainers

    CVE-2024-26855: when a missing attribute becomes a NULL dereference

    A Linux ice driver fix illustrates a common review mistake: treating a parser’s optional result as a guaranteed object.

    Read article
  3. CVE explainers

    CVE-2025-37858: a 64-bit destination cannot fix a narrow shift

    A JFS allocation-group calculation demonstrates why code review must inspect the width of an operation before its result is assigned.

    Read article