Crafting a Full Read SSRF: A Journey Through Oauth DCR, Open URL Redirects, and Path NormalizationThe Bug This blog post outlines the chains of multiple gadgets to achieve a full read ssrf on a target. Open Dynamic client registration on the MCP server to create an open redirect gadget Path normApr 6, 2026·8 min read
Bypassing Cloudflare WAF with comma symbol to gain RCE using a file upload vulnerability (Ethiack CTF)Sep 7, 2025·7 min read