https://trmm.net/TOCTOU/
TOCTOU - Trammell Hudson's Projects
Collection of my projects and hacks.
toctoutrammellhudsonprojects
https://commitfest.postgresql.org/patch/6682/
Fix TOCTOU race in ReplicationSlotsComputeRequiredLSN()
fixtoctourace
https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35352/
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition | GitLab Advisory...
CVE-2026-35352 uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition: A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in...
https://aws.amazon.com/security/security-bulletins/2026-025-aws/
CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight...
https://advisories.gitlab.com/maven/org.apache.tomcat/tomcat/CVE-2022-23181/
Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database (GLAD)
CVE-2022-23181 Time-of-check Time-of-use (TOCTOU) Race Condition: The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into...
race conditiontimecheckusetoctou
https://lists.freebsd.org/archives/freebsd-net/2026-April/008605.html
Re: kernel svc_rpc_gss_update_seq missing 2017 Coverity fix + TOCTOU with check_replay
https://advisories.gitlab.com/golang/go.etcd.io/etcd/v3/GMS-2022-5095/
etcd vulnerable to TOCTOU of gateway endpoint authentication | GitLab Advisory Database (GLAD)
GMS-2022-5095 etcd vulnerable to TOCTOU of gateway endpoint authentication: The vulnerability was spotted due to unclear documentation of how the gateway...
https://advisories.gitlab.com/npm/flowise/GHSA-2x8m-83vc-6wv4/
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure) | GitLab Advisory Database (GLAD)
ssrf protectionflowisebypasstoctou
https://advisories.gitlab.com/npm/openclaw/CVE-2026-32043/
OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host | GitLab Advisory...
CVE-2026-32043 OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host: In openclaw@2026.2.24, approval-bound system.run on node...
https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35364/
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database...
CVE-2026-35364 uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition: A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the...
https://codeql.github.com/codeql-standard-libraries/actions/codeql/actions/security/ControlChecks.qll/predicate.ControlChecks$non_toctou_category.0.html
non_toctou_category
API documentation for CodeQL
nontoctoucategory
https://advisories.gitlab.com/maven/org.apache.tomcat.embed/tomcat-embed-core/CVE-2022-23181/
Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database (GLAD)
CVE-2022-23181 Time-of-check Time-of-use (TOCTOU) Race Condition: The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into...
race conditiontimecheckusetoctou
https://aws.amazon.com/security/security-bulletins/rss/2026-025-aws/
CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight...
https://advisories.gitlab.com/npm/openclaw/CVE-2026-43529/
OpenClaw: TOCTOU read in exec script preflight | GitLab Advisory Database (GLAD)
CVE-2026-43529 OpenClaw: TOCTOU read in exec script preflight: OpenClaw's exec script preflight validator previously validated and then read a script by...
openclawtoctoureadexec
https://advisories.gitlab.com/nuget/magick.net-q8-anycpu/CVE-2026-28689/
ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD)
CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap...
https://advisories.gitlab.com/composer/magento/community-edition/CVE-2025-24430/
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory Database...
CVE-2025-24430 Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10,...
https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35356/
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition | GitLab Advisory...
CVE-2026-35356 uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition: A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the...
https://advisories.gitlab.com/pypi/pywbem/CVE-2013-6444/
PyWBEM TOCTOU vulnerability in certificate validation | GitLab Advisory Database (GLAD)
CVE-2013-6444 PyWBEM TOCTOU vulnerability in certificate validation: PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in...
certificate validationtoctouvulnerabilitygitlabadvisory
https://advisories.gitlab.com/golang/github.com/buildkite/elastic-ci-stack-for-aws/v6/CVE-2023-43741/
Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database (GLAD)
CVE-2023-43741 Time-of-check Time-of-use (TOCTOU) Race Condition: A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS...
race conditiontimecheckusetoctou
https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35376/
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database...
CVE-2026-35376 uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition: A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the...
https://advisories.gitlab.com/pypi/virtualenv/CVE-2026-22702/
virtualenv Has TOCTOU Vulnerabilities in Directory Creation | GitLab Advisory Database (GLAD)
CVE-2026-22702 virtualenv Has TOCTOU Vulnerabilities in Directory Creation: TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local...
virtualenvtoctouvulnerabilities
https://advisories.gitlab.com/nuget/magick.net-q8-x64/CVE-2026-28689/
ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD)
CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap...
https://advisories.gitlab.com/nuget/magick.net-q8-openmp-arm64/CVE-2026-28689/
ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD)
CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap...
https://advisories.gitlab.com/maven/org.apache.tomcat/tomcat-catalina/CVE-2024-50379/
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory...
CVE-2024-50379 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability...
apache tomcat
https://advisories.gitlab.com/composer/magento/project-community-edition/CVE-2025-49558/
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory Database...
CVE-2025-49558 Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Magento versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11,...
https://dev.to/piiiico/toctou-of-trust-why-agent-governance-must-be-continuous-40ma
TOCTOU of Trust: Why Agent Governance Must Be Continuous - DEV Community
Three breaches, one shape In early April 2026, three separate tools that millions of... Tagged with agents, trust, mcp, security.
agent governancemust betoctoutrust
https://advisories.gitlab.com/maven/org.apache.tomcat/tomcat-catalina/CVE-2024-56337/
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory...
CVE-2024-56337 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability...
apache tomcat
https://advisories.gitlab.com/nuget/magick.net-q16-hdri-x64/CVE-2026-28689/
ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD)
CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap...
https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35353/
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database...
CVE-2026-35353 uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition: The mkdir utility in uutils coreutils incorrectly applies permissions...
https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35374/
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database...
CVE-2026-35374 uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition: A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the...
https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-34368/
AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance |...
CVE-2026-34368 AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance: The transferBalance() method in...
https://es.mathworks.com/help/bugfinder/ref/certcrulefio45c.html
CERT C: Rule FIO45-C - Avoid TOCTOU race conditions while accessing files - MATLAB
Avoid TOCTOU race conditions while accessing files.
https://advisories.gitlab.com/nuget/magick.net-q16-hdri-openmp-x64/CVE-2026-28689/
ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD)
CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap...
https://groups.google.com/g/kubernetes-security-announce/c/-MFX60_wdOY
[Security Advisory] CVE-2020-8562: Bypass of Kubernetes API Server proxy TOCTOU
security advisory
https://nl.mathworks.com/help/bugfinder/ref/cwe367.html
CWE Rule 367 - Time-of-check Time-of-use (TOCTOU) Race Condition - MATLAB
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that...
race conditioncweruletime
https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35354/
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition | GitLab Advisory...
CVE-2026-35354 uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition: A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the...
https://advisories.gitlab.com/npm/openclaw/CVE-2026-41296/
OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile | GitLab Advisory Database...
CVE-2026-41296 OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile: Sandbox escape via TOCTOU race in remote FS bridge readFile
https://advisories.gitlab.com/cargo/remove_dir_all/GHSA-mc8h-8q98-g5hr/
Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in...
GHSA-mc8h-8q98-g5hr Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all: The remove_dir_all crate is...
race condition
https://advisories.gitlab.com/composer/magento/community-edition/CVE-2025-24432/
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory Database...
CVE-2025-24432 Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10,...
https://advisories.gitlab.com/nuget/magick.net-q16-x86/CVE-2026-28689/
ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD)
CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap...