ctipilot.ch

Hadrian

hadrian-labs · B · candidate

https://hadrian.io/blog

researchvulnslang: enfetch failures: 0quiet periods: 0last fetch: 2026-08-18

ADDED as candidate by 2026-08-18 (this run's single new candidate). Offensive-security vendor whose Vulnerability Alerts blog publishes original root-cause reversing rather than re-reporting: it reconstructed the GeoServer jsonArrayContains SQL injection from a single researcher post to a working exploit and published the service-dependent exploitation analysis (WFS 1.0 reaching top-level SQL where WFS 2.0's count wrapper traps the injection, and the pgJDBC behaviour that makes preferQueryMode irrelevant) that this run's deep dive rests on — detail that appeared in no advisory. Rated B: original first-hand vulnerability research, not a first-party vendor authority for the affected product. FETCH: `python3 tools/fetch_source.py url https://hadrian.io/blog/<slug>` returned the full article body directly this run (~179 KB raw) with no reader fallback needed; the listing path has not yet been exercised. Promote to active after 3 contributing runs.

Cited in 4 entries

Citation cadence

Citation days per ISO week (14 weeks of coverage span, total 3).