Post #2245018
2026-04-17 12:42 UTC
wake up babe, new slopnerability class dropped: find application X that _could_ be linked with some library Y that has a known vulnerability AND X could somehow be operated to reach said vulnerability in Y.
File slop report against X to claim your CVE badge and bug bounties.
(AFAICT this is neither about vendoring a vulnerable version of Y in X nor about vulnerable version of Y being concretely otherwise shipped somewhere where X could also be installed.)
Replies (0)
No replies.