#security
12 posts
Base64: it is neither encryption nor compression
Base64 turns 3 bytes into 4 printable characters, growing the payload by a third. It solves carrying binary through a text channel, not keeping anything secret.
Idempotency keys: the one write that makes retries safe
A network timeout does not mean the server did nothing. An idempotency key identifies the same request so the server replays the first result instead of executing again.
JSON canonicalization: why the same object hashes two ways
Key order, number formatting and escape style all change the bytes. A stable hash has to pin those rules at serialization, not hope JSON.stringify is deterministic.
Catastrophic backtracking: why a regex can pin a CPU
Nested quantifiers make the number of match attempts grow exponentially; (a+)+b can hang a process on one long non-matching input. Drop the nesting or put a timeout on it.
iframe sandbox: it narrows capability, it does not harden
The sandbox attribute starts by removing everything and allow-* adds pieces back. Getting the direction backwards is common: scripts stop running because that is the default.
Unicode normalization: why two identical-looking strings differ
An e-acute can be one code point or a base letter plus a combining mark. Normalize to NFC before comparing, storing or indexing, or duplicates quietly slip through.
URL encoding: spaces, plus signs and double encoding
A plus is a space in the query string and a literal plus in the path; the two positions encode the same character differently; encoding twice yields a plausible value that never matches.
SharePoint deserialisation RCE: CVE-2026-45659
A plain Site Member account is enough to run code on a SharePoint server. Microsoft rated exploitation unlikely, and CISA put it in the KEV catalogue with three days to remediate.
n8n unauthenticated RCE (Ni8mare): CVE-2026-21858
The form node skips Content-Type validation, so one application/json request makes it read an arbitrary file. The key inside the config forges an admin JWT, and a sandbox bypass turns that into RCE.
Cisco FMC unauthenticated Java deserialisation RCE: CVE-2026-20131
CVSS 10.0, no authentication, code execution as root, and 36 days of use as a zero-day by a ransomware crew. Breaking the firewall management hub hands over every policy and log with it.
Next.js incremental cache path traversal to RCE: CVE-2026-75604
One unescaped backslash turns the incremental cache into arbitrary file read and write on Windows, and the leaked Server Action encryption key forges a request that walks a React Flight property chain to Function.
React Router prototype pollution chained into RCE: CVE-2026-42211
turbo-stream v2 calls a constructor while rehydrating the TYPE_ERROR branch without checking where it came from. If the app already has a prototype pollution bug, that path reaches Function and two moderate flaws become RCE.
