Research · Disclosures

Vulnerabilities we found in software the world runs on

Real bugs, found, reproduced from scratch, and responsibly disclosed. Confirmed by the maintainers themselves. This is the work behind the audits, not marketing.

4
maintainer-confirmed
500M+
combined downloads
100%
responsible disclosure
CVE-2026-16033 · GHSA-9hcm-hxh5-7xxh (LXD) ↗  CVE-2026-81497 · GHSA-4qxq-p5hm-3q3p (Incus) ↗
High 8.5 Published · CVE assigned
Canonical LXD and Incus

A template-path traversal in the VM engine let attacker input write files anywhere on the host

A prior fix for a template-path traversal was added to the container driver but never ported to the virtual-machine (QEMU) driver. Through that gap the VM template path could read and write arbitrary files on the host, including creating root-owned files. The same flaw lived in both sibling projects, LXD (Canonical) and Incus, because they share the driver code, so each published its own advisory.

Reach
Ubuntu, LXD, Incus
Weakness
CWE-22 / 59
Our role
Found the incomplete-fix, independently reproduced, and responsibly disclosed. Published and credited to us by Canonical (CVE-2026-16033) and by Incus (CVE-2026-81497).
CVE-2026-27761 · GHSA-3pww-vcvm-3gmj ↗
Moderate 4.3 Accepted · CVE assigned
Gitea

Low-scope API token could read a private repository's commit history

A read-only, issues-only API token, one that should have zero access to code, could pull a private repo's full commit history (messages, SHAs, committer emails) through the RSS and Atom feed endpoints, while the same token was correctly blocked everywhere else. An incomplete-coverage gap in a recent scope fix.

Reach
373M+ pulls
Weakness
CWE-863 (auth)
Our role
Found, independently reproduced, and responsibly disclosed.
CVE-2026-55667 · GHSA-fmm7-x4gx-8jhr ↗
High 8.2 Published · CVE assigned
File Browser

A locked-down upload-only user could delete any file and wipe the database

A scoped user with only the Create permission, the most restricted account you can hand out, could delete files anywhere on the server (other tenants' data) and even delete the app's own database, wiping every user, share, and setting and locking the owner out. An incomplete fix of a prior symlink CVE.

Reach
100M+ pulls
Weakness
CWE-22 / 863
Our role
Found, independently reproduced, responsibly disclosed, and validated the maintainer's fix. Published as CVE-2026-55667, credited to us.
CVE-2026-63131 · GHSA-xp3c-3jw3-4vcr ↗
Moderate 6.0 Published · CVE assigned
OpenBao

A stricter deny policy was skipped for LIST, granting access it should have blocked

An operator could set an explicit deny on a sensitive path, yet if a broader list was allowed on a parent path, OpenBao still permitted the LIST, the stricter deny was not applied to list operations. A privilege boundary that policy authors would reasonably trust to hold. Found by watching a fixed HashiCorp Vault bug that still lived in the OpenBao fork.

Reach
Secrets vault
Weakness
CWE-863 (auth)
Our role
Found via cross-fork watch, independently reproduced, and responsibly disclosed. Published as CVE-2026-63131, credited to us.
Paid bounty
Critical-severity finding, responsibly disclosed and rewarded. Part of ongoing live bug-bounty research alongside the open-source disclosures above.
The next frontier we secure

AI-Agent and MCP Security

As Nigerian businesses wire AI agents and MCP tools into their stack, that becomes the new attack surface. We audit it with the same incomplete-fix and cross-fork methodology behind our published CVEs, and we publish the research in the open.

Security research, in the open ↗

If it is hiding in software trusted hundreds of millions of times, what is hiding in yours?

A single low-privilege user could read all the private code in one of these, or destroy the whole server in the other. We find the gaps others miss, then tell you how to close them. That is what a Securva audit does for your systems.

Get your Securva Snapshot or email us

Disclosure note: all testing was performed on our own self-hosted copies of this open-source software. We never test third-party systems without authorization. CVE identifiers are assigned by the maintainers after a fix ships; this page is updated as each advisory publishes.