striga-ai / CVE-2026-34486
PublicApache Tomcat Tribes EncryptInterceptor fail-open bypass, unauthenticated RCE PoC
This project offers a controlled demonstration of a security flaw in Apache Tomcat's team communication feature that lets unauthorized users run code remotely.
How It Works
You stumble upon this project while learning about security weaknesses in popular web software.
You download the simple demo package to your computer to try it out safely.
You follow the easy one-command guide to launch a safe test setup of the vulnerable software.
The demo creates and sends a pretend harmful message to show how outsiders could take control.
You give it a moment while the test runs and checks if the flaw was triggered.
The demo confirms success by showing evidence inside the test environment, helping you grasp the danger.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.