Atomicorp WAF Research Notes
Research Update - 2026-08-26
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2019-11043 | PHP-FPM Path Info Buffer Underflow - Remote Code Execution | 390714 |
| CVE-2026-45018 | Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-80104 | DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename | 340007 , 344360 , 390709 |
| CVE-2026-80138 | ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2020-10221 | rConfig <= 3.9.4 - Authenticated OS Command Injection | 344364 , 344366 |
| CVE-2026-55585 | QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr() | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-62865 | TypeBot: Arbitrary server file read via Send Email block attachment path | 340007 , 344360 , 390709 |
| CVE-2026-23536 | Feast Feature Server <=0.58.0 - Arbitrary File Read | 344360 , 390709 |
| CVE-2026-45019 | Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-55537 | PraisonAI: Webhook SSRF via DNS fail-open in JobSubmitRequest.validate_webhook_url() — bypass of CVE-2026-40114 | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-79788 | Dradis Community Edition 5.1.0 through 5.2.0 Server-Side Request Forgery via Unrestricted AI Provider Address | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-79786 | Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration | 344365 |
| CVE-2026-79773 | Winter CMS before 1.2.13 Local File Inclusion via JavaScript | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-79717 | Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restriction | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-38472 | forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-79804 | SililaWijesinghe Food Ordering System search.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-79845 | code-projects Simple Inventory System edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-38467 | the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-38473 | the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-55419 | Reachy Mini: Unrestricted Upload of File with Dangerous Type | 351000 |
| CVE-2026-26211 | Ekushey Project Manager CRM 5.0 Stored XSS via System Name Field | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-38468 | the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-42188 | Geyser: Server-Side Request Forgery (SSRF) via Player Head Texture URL | 337109 , 337110 , 398021 , 398022 |
| CVE-2026-79793 | code-projects Online Shopping System sumit_form.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |