Blog

Security research, CVE writeups, and insights from Kira.

Subscribe via RSS
CVE GHSA-rrv8-h7p8-rx55 · August 2026

One Regex to Freeze Them All: ReDoS in NLTK’s Text.findall()

NLTK’s Text.findall() passes user-supplied patterns to Python’s re engine with no timeout and no complexity check. One request freezes the process indefinitely. CVSS 7.5 High, fixed in 3.10.0.

CVSS 7.5 High ReDoS NLTK
ANALYSIS · July 2026

OpenAI Open-Sourced Codex Security. Here’s How It Compares to Kira.

OpenAI released an LLM-only application security agent. We studied the codebase. Here’s what we found and why Kira chose a different architecture.

Architecture Comparison Codex Security OpenAI
CVE CVE-2026-53945 · June 2026

Ghost Had the SSRF Fix Written. It Just Wasn’t Plugged In.

Ghost maintained a hardened, DNS-rebinding-resistant HTTP library and used it everywhere except webhook delivery, the one place where an admin directly controls the target URL.

CVSS 5.5 Medium SSRF Ghost
CVE CVE-2026-50160 · May 2026

Kira Found a CVSS 10.0 Full Compromise in Hoppscotch: Four Weaknesses. One Exploit.

One unauthenticated HTTP request. No login, no token, no credentials. Four independent weaknesses spread across the codebase, none dangerous alone, catastrophic together.

CVSS 10.0 Critical Mass Assignment Hoppscotch

New CVE writeups & research, in your inbox.

No marketing. Just security findings, attack breakdowns, and research from the Offgrid team when we publish.

No spam. Unsubscribe anytime.