<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <title>miso</title>
  <subtitle>Security research notes</subtitle>
  <id>https://hacchoomiso.github.io/feed.xml</id>
  <link rel="self" type="application/atom+xml" href="https://hacchoomiso.github.io/feed.xml"/>
  <link rel="alternate" type="application/atom+xml" hreflang="ja" href="https://hacchoomiso.github.io/feed.ja.xml"/>
  <link rel="alternate" type="text/html" href="https://hacchoomiso.github.io/blog/"/>
  <icon>https://hacchoomiso.github.io/favicon.svg</icon>
  <updated>2026-10-03T00:00:00+09:00</updated>
  <author><name>miso</name></author>
  <entry>
    <title>One Byte Too Far: Heap Buffer Overflow in Apache HTTP Server's mod_heartmonitor</title>
    <link rel="alternate" type="text/html" href="https://hacchoomiso.github.io/blog/OSS/CVE-2026-46729/"/>
    <link rel="alternate" type="text/html" hreflang="ja" href="https://hacchoomiso.github.io/blog/OSS/CVE-2026-46729/ja/"/>
    <id>https://hacchoomiso.github.io/blog/OSS/CVE-2026-46729/</id>
    <published>2026-10-03T00:00:00+09:00</published>
    <updated>2026-10-03T00:00:00+09:00</updated>
    <summary>An unauthenticated one-byte heap buffer overflow in Apache HTTP Server's mod_heartmonitor (CVE-2026-46729), present since 2009 — independently discovered and credited as a co-finding.</summary>
  </entry>
  <entry>
    <title>The Unguarded Setting: GPU-to-Browser Sandbox Escape in Chrome via GTK3's Gtk/Modules XSETTING</title>
    <link rel="alternate" type="text/html" href="https://hacchoomiso.github.io/blog/Chrome/CVE-2026-76023/"/>
    <link rel="alternate" type="text/html" hreflang="ja" href="https://hacchoomiso.github.io/blog/Chrome/CVE-2026-76023/ja/"/>
    <id>https://hacchoomiso.github.io/blog/Chrome/CVE-2026-76023/</id>
    <published>2026-09-22T00:00:00+09:00</published>
    <updated>2026-09-22T00:00:00+09:00</updated>
    <summary>A compromised Linux/X11 GPU process could make GTK3 execute an attacker-controlled memfd in Chrome's browser process via the Gtk/Modules XSETTING (CVE-2026-76023, issue 545124048).</summary>
  </entry>
  <entry>
    <title>The Fourth Pickle: Unauthenticated Remote Code Execution in SGLang's Disaggregated Diffusion Server</title>
    <link rel="alternate" type="text/html" href="https://hacchoomiso.github.io/blog/SGLang/CVE-2026-93088/"/>
    <link rel="alternate" type="text/html" hreflang="ja" href="https://hacchoomiso.github.io/blog/SGLang/CVE-2026-93088/ja/"/>
    <id>https://hacchoomiso.github.io/blog/SGLang/CVE-2026-93088/</id>
    <published>2026-09-22T00:00:00+09:00</published>
    <updated>2026-09-22T00:00:00+09:00</updated>
    <summary>Unauthenticated remote code execution in SGLang's disaggregated diffusion server (CVE-2026-93088, VU#727584, GHSA-8374-wrr5-7q7f), plus nine additional findings verified against upstream code.</summary>
  </entry>
</feed>
