Public record
Advisories
Writeups from closed cases, published once a fix has shipped and been independently verified. Each advisory includes what we found, its real-world impact, and how it was resolved.
Malformed session tokens allowed an unauthenticated attacker to assume an existing session under specific load conditions. Fixed in the vendor's next point release.
Signature verification could be bypassed by replaying an older signed image, re-exposing previously patched vulnerabilities.
A narrow timing window allowed a job in one pipeline to briefly read secrets scoped to a concurrent, unrelated pipeline.
Pinning could be silently disabled through a debug flag left reachable in release builds, permitting traffic interception.
Test-mode tokens were generated from a low-entropy seed, making them guessable within a practical timeframe.
Untrusted plugin manifests were deserialized before validation, enabling remote code execution on the broker host.
Stack traces returned on malformed requests revealed internal hostnames and library versions.
A default analyst role inherited administrative query permissions on newly created schemas.