Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Alert Feeds
  • Firedancer Solana Validator – QUIC Transport Parameter UB and Consensus-Splitting Cast Bug  – Full Disclosure
AttackFeed by Joe Wagner | Firedancer Solana Validator - QUIC Transport Parameter UB and Consensus-Splitting Cast Bug  - Full Disclosure

Firedancer Solana Validator – QUIC Transport Parameter UB and Consensus-Splitting Cast Bug  – Full Disclosure

Posted on February 16, 2026 By Joe-W
Alert Feeds

 

Posted by Agent Spooky’s Fun Parade via Fulldisclosure on Feb 16

1. SUMMARY

Two independently confirmed vulnerabilities in Jump Crypto’s Firedancer
Solana validator (https://github.com/firedancer-io/firedancer, commit
7cd3b6dce):

A) Three undefined behavior / logic bugs in QUIC transport parameter
processing, triggerable by a malicious QUIC server with zero
authentication. Enables remote connection kill or hang.

B) Incorrect Rust saturating cast emulation that returns ULONG_MAX…
 – Read More  – Full Disclosure 

Post navigation

❮ Previous Post: 🚨 Public Disclosure: Remote BitLocker Bypass via Intel AMT — SYSTEM Access Without Login  – Full Disclosure
Next Post: [SYSS-2025-014] Linksys MX4200 – Improper Verification of Source of a Communication Channel  – Full Disclosure ❯

You may also like

AttackFeed by Joe Wagner | Alipay DeepLink+JSBridge Attack Chain: Silent GPS Exfiltration, 17 Vulns, 6 CVEs (CVSS 9.3)  - Full Disclosure
Alert Feeds
Alipay DeepLink+JSBridge Attack Chain: Silent GPS Exfiltration, 17 Vulns, 6 CVEs (CVSS 9.3)  – Full Disclosure
March 12, 2026
AttackFeed by Joe Wagner | SEC Consult SA-20260401-0 :: Broken Access Control in Open WebUI  - Full Disclosure
Alert Feeds
SEC Consult SA-20260401-0 :: Broken Access Control in Open WebUI  – Full Disclosure
April 3, 2026
AttackFeed by Joe Wagner | Apple OHTTP Relay: 14 Third-Party Endpoints, 6 Countries, Zero User Visibility  - Full Disclosure
Alert Feeds
Apple OHTTP Relay: 14 Third-Party Endpoints, 6 Countries, Zero User Visibility  – Full Disclosure
April 3, 2026
AttackFeed by Joe Wagner | APPLE-SA-02-11-2026-8 visionOS 26.3  - Full Disclosure
Alert Feeds
APPLE-SA-02-11-2026-8 visionOS 26.3  – Full Disclosure
February 16, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.