Featured Posts
All Posts

Security
Sep 10, 2026
CVE-2026-19203, CVE-2026-12611 & CVE-2026-19204: Three Jetty Protocol-Parser Flaws Hit EOL 9.4, 10.0, and 11.0
How a lone line feed, an HTTP/2 teardown race, and an unvalidated WebSocket opcode each let a remote unauthenticated client smuggle requests or take a Jetty server down, with no OSS fix for the 9.4, 10.0, and 11.0 lines.
Greg Allen

Security
Sep 10, 2026
Node.js 20 on Google Cloud: October 30 Decommission and Your Options
Upgrading runtimes is rarely top of mind until a deadline forces your hand, and for Node.js 20 runtime in Google Cloud services, that deadline is less than two months away.
Javier Perez

Security
Sep 10, 2026
CVE-2026-59313: Spring Framework Server-Sent Events Injection, Scored 9.8 Critical
Spring Framework is the foundation under most of the Java web tier, and its Spring MVC layer includes a functional web framework (WebMvc.fn) where you build endpoints as route handlers instead of annotated controllers.
Mark Szymanski

Security
Sep 9, 2026
CVE-2026-47892 and CVE-2026-59283: Two Spring "Critical" Ratings
How two CISA-ADP Critical scores landed on Spring Framework bugs that require non-default configuration to reach, and the five-minute check that tells you which score describes your deployment.
Greg Allen

Security
Sep 8, 2026
CVE-2026-62871: .NET WPF Heap Overflow Enables Local Code Execution
How a crafted TrueType font wraps unsigned 16-bit loop counters in WPF's font subsetter, writes past its heap buffer, and hands code execution to whoever gets a document opened.
Greg Allen

Security
Sep 8, 2026
CVE-2026-34486: Apache Tomcat EncryptInterceptor Fail-Open Bypass
How a one-line refactor moved cluster-message decryption from fail-closed to fail-open, letting an unauthenticated attacker reach Tomcat's Java deserialization path on port 4000.
Greg Allen

Compliance
Sep 8, 2026
Ingress NGINX Is End of Life: How to Keep It Secure on AWS With NES
If you run EKS, AWS's managed Kubernetes offering, there is a good chance Ingress NGINX still sits in your production traffic path.
Justin Gorny

Security
Sep 7, 2026
Node.js CVE Round-Up: 11 New Vulnerabilities Affecting EOL Node.js 20
HeroDevs patched all eleven vulnerabilities across end-of-life (EOL) Node.js 12–20
Javier Perez

Migration
Sep 2, 2026
Upgrade or Buy Extended Support for an EOL Framework: How to Decide
Migration and extended support are not opposites. A simple framework for deciding which one fits your timeline.
Maria Spano

EOL Software
Aug 31, 2026
Drupal 7 End of Life: What It Means and What to Do Now
Drupal 7 has been end-of-life since January 2025, with new module vulnerabilities still surfacing every month.
Javier Perez

EOL Software
Aug 28, 2026
Running Node.js 20 on AWS: What Deprecation Actually Means and What Your Options Are
Navigating AWS Deprecation Policies and Securing Legacy Runtimes Beyond EOL
Javier Perez

Security
Aug 28, 2026
Apache Log4j Versions, EOL Dates, and Latest Releases (August 2026)
A complete reference for every Log4j release line, the Log4Shell retrospective, and the seven CVEs disclosed since December 2025 that stop at Log4j 2.25.x.
Greg Allen

Compliance
Aug 28, 2026
Does Running EOL Software Violate PCI DSS, HIPAA, or SOC 2?
EOL software is not an automatic violation, but it lands on the wrong side of the controls these frameworks enforce.
Rob Nalen

Compliance
Aug 27, 2026
Six Reasons Why Low-Severity CVEs Become High Risk
AI-driven vulnerability landscape rewrites triage math, especially for end-of-life (EOL) software.
Javier Perez

Security
Aug 27, 2026
91 Spring CVEs in a Single Day: Inside the August 2026 Batch
Understanding the shift in Spring project security disclosures and what this record-breaking batch means for your Java dependency tree.
Mark Szymanski
.png)
.png)
.png)