DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Fuzzing for fun - unauthenticated denial of service in snac2

Quality: 8/10 Relevance: 9/10

Summary

A technical blog post documenting fuzzing the snac2 JSON parser to uncover a remote, unauthenticated denial-of-service vulnerability. The author explains the target, fuzzing setup with AFL++, the crash caused by a null byte in sequences, the underlying memory handling bug, and a commit that fixes the issue, with discussion on CVE disclosure.

🚀 Service construit par Johan Denoyer