Atomicorp WAF Research Notes

Research Update - 2026-08-26

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2019-11043PHP-FPM Path Info Buffer Underflow - Remote Code Execution390714
CVE-2026-45018Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-80104DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename340007 , 344360 , 390709
CVE-2026-80138ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2020-10221rConfig <= 3.9.4 - Authenticated OS Command Injection344364 , 344366
CVE-2026-55585QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr()340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-62865TypeBot: Arbitrary server file read via Send Email block attachment path340007 , 344360 , 390709
CVE-2026-23536Feast Feature Server <=0.58.0 - Arbitrary File Read344360 , 390709
CVE-2026-45019Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-55537PraisonAI: Webhook SSRF via DNS fail-open in JobSubmitRequest.validate_webhook_url() — bypass of CVE-2026-40114337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-79788Dradis Community Edition 5.1.0 through 5.2.0 Server-Side Request Forgery via Unrestricted AI Provider Address337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-79786Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration344365
CVE-2026-79773Winter CMS before 1.2.13 Local File Inclusion via JavaScript340007 , 344360 , 347009 , 390709
CVE-2026-79717Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restriction337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-38472forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-79804SililaWijesinghe Food Ordering System search.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79845code-projects Simple Inventory System edit.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-38467the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-38473the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-55419Reachy Mini: Unrestricted Upload of File with Dangerous Type351000
CVE-2026-26211Ekushey Project Manager CRM 5.0 Stored XSS via System Name Field333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-38468the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-42188Geyser: Server-Side Request Forgery (SSRF) via Player Head Texture URL337109 , 337110 , 398021 , 398022
CVE-2026-79793code-projects Online Shopping System sumit_form.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148