TFSec
ABOUTWORKTEAMRECORDSBLOGCVEs

[ BLOG ]

PUBLISHED WORK

Security research, CVEs we found, and interesting vulnerabilities. Everything here is written from experience.

SSRFCVE-2026-14646Nexus Repository ManagerSonatypeCloud SecurityHackerOne
2026-08-03

SSRF Redirect Bypass in Sonatype Nexus, Stealing Cloud Credentials Through a Proxy Repository (CVE-2026-14646)

Sonatype Nexus Repository Manager had SSRF protection that blocked requests to cloud metadata endpoints. But it only validated the initial URL. A single HTTP redirect bypassed everything. Full technical breakdown of CVE-2026-14646.

E
@e0x1337
8 min readREAD →
LATEST
WooCommerceStripeBusiness LogicPayment SecurityHackerOne
2026-08-03

Cart Swap Attack on Stripe for WooCommerce, From Session Hijack to Full Payment Bypass

A deep dive into how a missing ownership check on a single WooCommerce AJAX endpoint let attackers rewrite Stripe payment amounts mid checkout. Includes the full attack flow, root cause analysis, and what every developer should learn from it.

E
@e0x1337
9 min readREAD →
CVEAdobeVulnerability ResearchDoSPath Traversal
2026-07-14

31 CVEs in Adobe Content Credentials SDK & Adobe Commerce

We spent months digging into Adobe's Content Credentials SDK and Adobe Commerce. Ended up with 31 CVEs across three security bulletins.

B
@bau1u
2 min readREAD →
Announcement
2026-07-08

Welcome to TFSec

Who we are, what we do, and what you can expect from this blog.

B
@bau1u
1 min readREAD →
TFSec

Want to collab, join the team, or just chat? [email protected]

© 2026 TFSec. Malaysia.