Featured Posts
All Posts

EOL Software
Jul 23, 2026
Hibernate 6.6 Isn't End-of-Life. It's in "Limited Support." That Distinction Matters.
Navigating the security risks of Hibernate’s "limited-support" phase and preparing your applications for the shift to End-of-Life.
Mark Szymanski
.png)
Security
Jul 22, 2026
CVE-2026-55602: http-proxy-middleware router Host-Header Routing Bypass
How unanchored substring matching in the router proxy-table lets a crafted Host header route requests to an unintended backend
Greg Allen
.png)
Security
Jul 21, 2026
CVE-2026-42533: Critical NGINX Heap Overflow Hits EOL Ingress-NGINX
How an ordering bug in NGINX's two-pass script engine lets an unauthenticated request corrupt worker memory in EOL Ingress NGINX
Justin Gorny

Security
Jul 21, 2026
Spring Boot Managed Dependencies Still Get CVEs After EOL: July 2026 Patch Round-Up
13 upstream CVEs landed across Netty, Tomcat, Logback, pgjdbc, and Jackson this month, with three of them High-severity. Which Boot version you run determines which fixes reach you.
Erik Weibust

Security
Jul 20, 2026
Spring Boot Managed Dependencies Still Get CVEs After EOL: June 2026 Patch Round-Up
18 upstream CVEs landed in a single Netty release this month, and every one of them is reachable through the Spring Boot managed-dependency BOM on EOL lines that pin Netty 4.1.
Erik Weibust

Security
Jul 17, 2026
The White House’s “Gold Eagle” Clearinghouse Makes “Secure in Place” A Requirement for Combatting AI-Scale Vulnerability Discovery
As AI accelerates vulnerability discovery, enterprises need lifecycle visibility and a secure-in-place strategy to protect unsupported, business-critical software.
Greg Allen

Compliance
Jul 16, 2026
The $258,000 Fork: Why DIY Compliance Workarounds Are a Tech-Debt Trap
Uncovering the hidden $258,000 cost of maintaining private open source forks and navigating CRA compliance.
Taylor Corbett

Security
Jul 16, 2026
CVE-2026-10050: Jetty Digest Authentication Bypass (ISO-8859-1)
How lossy ISO-8859-1 encoding in Jetty's Digest auth client lets an attacker authenticate with a collision password
Greg Allen

EOL Software
Jul 14, 2026
Java 8, 11, 17 EOL Dates by OpenJDK Vendor: Temurin to Red Hat
Every JDK vendor's end-of-life date for Java 8, 11, 17, and 21 in one place, and what those dates mean for the frameworks pinned to them.
Greg Allen
.png)
EOL Software
Jul 9, 2026
Node.js June 2026 Security Releases: Patches for EOL Node 18 and 20
Addressing June 2026 CVEs and Providing Security Coverage for End-of-Life Versions
Greg Allen

Security
Jul 8, 2026
CVE-2026-50169, CVE-2026-50184 & CVE-2026-54264: Angular Service Worker Request-Policy Stripping
How the Angular Service Worker discards client-defined request policy during asset reconstruction, leaking credentials and following redirects the application meant to block
Greg Allen

EOL Software
Jul 8, 2026
The Nursing Home of the Internet: Why End-of-Life Open Source Is Your Biggest Hidden Liability
Why End-of-Life Open Source Is Your Biggest Hidden Liability
Taylor Corbett

EOL Software
Jul 7, 2026
Next.js EOL Dates: Version Support Timeline (9 Through 16)
A complete reference for every Next.js release timeline, the CVEs hitting end-of-life versions, and what teams running Next.js 13 and earlier need to do now.
Javier Perez
.png)
Compliance
Jul 6, 2026
The CRA Readiness Gap: Why Most Organizations Aren’t Ready for December 2027 — and What to Do About It
Navigating the EU’s Cyber Resilience Act and the urgency of the 2027 deadline
Taylor Corbett
.png)
EOL Software
Jul 3, 2026
Bootstrap End of Life Dates: Bootstrap 2, 3, 4, and 5 (2026 Guide)
A complete reference for every Bootstrap major version, its release timeline, end-of-life date, and the CVEs still actively affecting unsupported releases.
Greg Allen
.png)
.png)
.png)