
When the Request Picks the Algorithm: HMAC Downgrade in Symfony's Mailomat Webhook Parser (CVE-2026-48747)
The webhook signature header names its own hash algorithm, so the attacker picks the weakest one. CVE-2026-48747.
Security researcher
Write-ups from vulnerabilities I found and reported.

The webhook signature header names its own hash algorithm, so the attacker picks the weakest one. CVE-2026-48747.

A hardlink inside a tar archive walks out of the extraction directory and overwrites files on the Kubernetes host node.