<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/black-hat-usa-2026-parties-events-guide/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T18:33:09.000Z</news:publication_date>
      <news:title>Black Hat USA 2026 Parties &amp;#038; Events: The Complete Guide (with DEF CON 34)</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/axios-prototype-pollution-proxy-hijack-interceptor-config</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:50:27.496Z</news:publication_date>
      <news:title>axios Node HTTP Adapter Prototype Pollution Proxy Hijack via Interceptor Config Cloning</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-67725-tornado-httpheaders-quadratic-dos-repeated-headers</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T19:08:39.101Z</news:publication_date>
      <news:title>CVE-2025-67725: Tornado HTTPHeaders Quadratic DoS via Repeated Header Coalescing</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-67726-tornado-multipart-parseparam-quadratic-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T19:08:00.383Z</news:publication_date>
      <news:title>CVE-2025-67726: Tornado Quadratic DoS via Crafted Multipart Parameters</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-13311-shell-quote-quadratic-dos-parse</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:10:33.827Z</news:publication_date>
      <news:title>CVE-2026-13311: shell-quote Quadratic Complexity DoS in parse()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47302-encryptedxml-nested-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:49:13.083Z</news:publication_date>
      <news:title>CVE-2026-47302: System.Security.Cryptography.Xml EncryptedXml Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50524-dotnet-tls-handshake-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:10:52.413Z</news:publication_date>
      <news:title>CVE-2026-50524: .NET TLS Handshake Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50525-dotnet-encryptedxml-cipherreference-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:09:01.007Z</news:publication_date>
      <news:title>CVE-2026-50525: System.Security.Cryptography.Xml EncryptedXml Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50528-dotnet-sslstream-tls-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:09:29.070Z</news:publication_date>
      <news:title>CVE-2026-50528: .NET SslStream TLS Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50648-encryptedxml-nested-dos-resource-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:10:15.322Z</news:publication_date>
      <news:title>CVE-2026-50648: System.Security.Cryptography.Xml EncryptedXml Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53515-better-auth-sso-bola-register-provider</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:08:02.302Z</news:publication_date>
      <news:title>CVE-2026-53515: @better-auth/sso Broken Object-Level Authorization on SSO Provider Registration</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54058-pillow-mcidas-oob-read-mmap-stride</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:48:47.857Z</news:publication_date>
      <news:title>CVE-2026-54058: Pillow Out-of-Bounds Read via Undersized McIdas AREA Row Stride</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54059-pillow-pcffontfile-decompression-bomb-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:51:15.511Z</news:publication_date>
      <news:title>CVE-2026-54059: Pillow PcfFontFile Decompression Bomb Protection Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54060-pillow-fontfile-compile-decompression-bomb-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:30:37.778Z</news:publication_date>
      <news:title>CVE-2026-54060: Pillow FontFile.compile() Decompression Bomb Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54560-cloudreve-oauth-scope-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:29:48.976Z</news:publication_date>
      <news:title>CVE-2026-54560: Cloudreve OAuth Access Token Scope Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55379-pillow-bdffontfile-decompression-bomb-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:29:50.106Z</news:publication_date>
      <news:title>CVE-2026-55379: Pillow BdfFontFile Decompression Bomb Protection Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55380-pillow-gdimagefile-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:51:06.544Z</news:publication_date>
      <news:title>CVE-2026-55380: Pillow GdImageFile Decompression Bomb (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55514-vllm-mrope-prompt-embeds-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T19:28:51.145Z</news:publication_date>
      <news:title>CVE-2026-55514: vLLM Denial of Service via Prompt Embeds on M-RoPE Models</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55667-filebrowser-scopedfs-removeall-symlink-deletion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:29:15.182Z</news:publication_date>
      <news:title>CVE-2026-55667: File Browser Out-of-Scope File Deletion via Symlink-Following RemoveAll</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-57108-dotnet-runtime-x509-nameinfo-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:49:48.269Z</news:publication_date>
      <news:title>CVE-2026-57108: .NET Runtime X.509 Certificate Parsing Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59197-pillow-rankfilter-integer-overflow-heap-oob-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:48:06.904Z</news:publication_date>
      <news:title>CVE-2026-59197: Pillow Heap Out-of-Bounds Write via Integer Overflow in RankFilter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59199-pillow-heap-oob-write-paste-crop-integer-overflow</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:30:15.960Z</news:publication_date>
      <news:title>CVE-2026-59199: Pillow Heap Out-of-Bounds Write via Signed Coordinate Overflow</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59200-pillow-pdfparser-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:29:31.412Z</news:publication_date>
      <news:title>CVE-2026-59200: Pillow PdfParser Decompression Bomb DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59204-pillow-jpeg2000-tiled-decode-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:28:47.936Z</news:publication_date>
      <news:title>CVE-2026-59204: Pillow JPEG2000 Tiled Decode Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59205-pillow-imagecms-heap-oob-write-mode-mismatch</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:28:09.955Z</news:publication_date>
      <news:title>CVE-2026-59205: Pillow Controlled Heap Out-of-Bounds Write in ImageCmsTransform.apply()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59725-engine-io-polling-connection-exhaustion-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:09:58.620Z</news:publication_date>
      <news:title>CVE-2026-59725: engine.io Polling Transport Connection Exhaustion (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59731-astro-middleware-authorization-bypass-decode-iteration</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:08:00.647Z</news:publication_date>
      <news:title>CVE-2026-59731: Astro Middleware Authorization Bypass via URL Decode Iteration Limit</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59869-js-yaml-merge-key-quadratic-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:28:34.464Z</news:publication_date>
      <news:title>CVE-2026-59869: js-yaml Merge-Key Chain Quadratic CPU DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59874-node-tar-infinite-loop-negative-entry-size</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:09:17.085Z</news:publication_date>
      <news:title>CVE-2026-59874: node-tar Infinite Loop via Negative Base-256 Entry Size</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59922-mistune-quadratic-dos-formatting-plugins</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:49:33.963Z</news:publication_date>
      <news:title>CVE-2026-59922: mistune Quadratic Parsing DoS in Formatting Plugins</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59928-mistune-quadratic-reflink-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:28:01.632Z</news:publication_date>
      <news:title>CVE-2026-59928: mistune Quadratic-Time ReDoS via Reference-Link Definitions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61736-lightrag-cors-wildcard-credentials</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:48:51.361Z</news:publication_date>
      <news:title>CVE-2026-61736: lightrag-hku CORS Wildcard + Credentials Any-Origin Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61740-lightrag-hardcoded-jwt-secret-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:48:13.747Z</news:publication_date>
      <news:title>CVE-2026-61740: LightRAG Authentication Bypass via Hardcoded JWT Secret and Guest Token Short-Circuit</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61835-directus-ssrf-0000-bypass-file-import</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:29:17.137Z</news:publication_date>
      <news:title>CVE-2026-61835: Directus SSRF Protection Bypass via 0.0.0.0 in File Import</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62685-filebrowser-username-normalization-home-directory-collision</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:28:04.043Z</news:publication_date>
      <news:title>CVE-2026-62685: File Browser Username Normalization Home Directory Collision</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>