<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
	<title>pepdep</title>
	<link>https://pepdep.com</link>
	<description>Security research and write-ups.</description>
	<language>en</language>
	<atom:link href="https://pepdep.com/feed.xml" rel="self" type="application/rss+xml" />
		<item>
		<title>Two parsers, one signature</title>
		<link>https://pepdep.com/posts/two-parsers-one-signature</link>
		<guid isPermaLink="true">https://pepdep.com/posts/two-parsers-one-signature</guid>
		<pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
		<description>Intigriti challenge 0726. A duplicate key in a signed JSON manifest let an ordinary account pull a report out of a namespace it was never granted. The signature stayed valid the whole way through.</description>
	</item>
	</channel>
</rss>
