Latest articles
Application security blog
CVE explainers, code review patterns and practical guidance for people who build and own software.
After React2Shell: three security boundaries every server component review needs
A technical review method for React2Shell and CVE-2026-23864: separate safe decoding, permission checks and bounded work, then verify the deployed build.
Read articleCVE-2024-26855: when a missing attribute becomes a NULL dereference
A Linux ice driver fix illustrates a common review mistake: treating a parser’s optional result as a guaranteed object.
Read articleCVE-2025-37858: a 64-bit destination cannot fix a narrow shift
A JFS allocation-group calculation demonstrates why code review must inspect the width of an operation before its result is assigned.
Read article