All Posts

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Security

Apr 2, 2026

The Supply Chain Attack Playbook: Why Package Ecosystems Keep Getting Compromised

Why maintainer accounts are the weakest link in modern package ecosystems—and what needs to change

Allison Vorthmann

Allison Vorthmann

Share this post via:

herodevs.com/blog-posts/
the-supply-chain-attack-playbook-why-package-ecosystems-keep-getting-compromised

Security

Apr 1, 2026

CVE-2025-1647: Bootstrap 3 XSS Vulnerability via DOM Clobbering in Tooltip and Popover Components

How a DOM clobbering flaw in Bootstrap 3 bypasses HTML sanitization—and what teams can do about it

Greg Allen

Greg Allen

Share this post via:

herodevs.com/blog-posts/
cve-2025-1647-bootstrap-3-xss-vulnerability-via-dom-clobbering-in-tooltip-and-popover-components

Security

Apr 1, 2026

CVE-2026-22022 and CVE-2026-22444: Apache Solr Authorization Bypass and File-Access Vulnerabilities Explained

Breaking down Solr’s latest security flaws and how to protect EOL and production systems

Greg Allen

Greg Allen

Share this post via:

herodevs.com/blog-posts/
cve-2026-22022-and-cve-2026-22444-apache-solr-authorization-bypass-and-file-access-vulnerabilities-explained

Security

Mar 31, 2026

HeroDevs Now Publishes VEX Data: Fewer False Positives, Less Noise

HeroDevs Now Publishes OpenVEX Data So Your Scanning Tools Can Automatically Filter Out the Noise

Edward Ezekiel

Edward Ezekiel

Share this post via:

herodevs.com/blog-posts/
herodevs-now-publishes-vex-data-fewer-false-positives-less-noise

Products

Mar 30, 2026

Ruby on Rails End-of-Life Versions: The Dual Ruby + Rails EOL Problem Enterprises Face in 2026

Why Running EOL Ruby and Rails Together Creates Compounding Security Risk—and What to Do About It

Greg Allen

Greg Allen

Share this post via:

herodevs.com/blog-posts/
ruby-on-rails-end-of-life-versions-the-dual-ruby-rails-eol-problem-enterprises-face-in-2026

Security

Mar 26, 2026

March 2026 Spring CVE Roundup: Six New Vulnerabilities Patched Across the Spring Ecosystem

Spring Security Alert: 6 Critical CVEs Impact Boot, Framework, and Legacy EOL Systems

HeroDevs

HeroDevs

Share this post via:

herodevs.com/blog-posts/
march-2026-spring-cve-roundup-six-new-vulnerabilities-patched-across-the-spring-ecosystem

Security

Mar 25, 2026

CVE-2026-29057 and CVE-2026-27980: Two New Vulnerabilities Affecting End-of-Life Next.js

How HeroDevs NES secures end-of-life Next.js applications against DoS and request smuggling threats

Javier Perez

Javier Perez

Share this post via:

herodevs.com/blog-posts/
cve-2026-29057-and-cve-2026-27980-two-new-vulnerabilities-affecting-end-of-life-next-js

Security

Mar 24, 2026

Spring Boot Authentication Bypass: Two New CVEs That Enterprise Teams Cannot Afford to Ignore ( CVE-2026-22731, CVE-2026-22733)

HIGH | March 19, 2026 | CVE-2026-22731, CVE-2026-22733

Mark Szymanski

Mark Szymanski

Share this post via:

herodevs.com/blog-posts/
spring-boot-authentication-bypass-two-new-cves-that-enterprise-teams-cannot-afford-to-ignore-cve-2026-22731-cve-2026-22733