Robuta

https://trmm.net/TOCTOU/ TOCTOU - Trammell Hudson's Projects Collection of my projects and hacks. toctoutrammellhudsonprojects https://commitfest.postgresql.org/patch/6682/ Fix TOCTOU race in ReplicationSlotsComputeRequiredLSN() fixtoctourace https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35352/ uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition | GitLab Advisory... CVE-2026-35352 uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition: A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in... https://aws.amazon.com/security/security-bulletins/2026-025-aws/ CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight... https://advisories.gitlab.com/maven/org.apache.tomcat/tomcat/CVE-2022-23181/ Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database (GLAD) CVE-2022-23181 Time-of-check Time-of-use (TOCTOU) Race Condition: The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into... race conditiontimecheckusetoctou https://lists.freebsd.org/archives/freebsd-net/2026-April/008605.html Re: kernel svc_rpc_gss_update_seq missing 2017 Coverity fix + TOCTOU with check_replay https://advisories.gitlab.com/golang/go.etcd.io/etcd/v3/GMS-2022-5095/ etcd vulnerable to TOCTOU of gateway endpoint authentication | GitLab Advisory Database (GLAD) GMS-2022-5095 etcd vulnerable to TOCTOU of gateway endpoint authentication: The vulnerability was spotted due to unclear documentation of how the gateway... https://advisories.gitlab.com/npm/flowise/GHSA-2x8m-83vc-6wv4/ Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure) | GitLab Advisory Database (GLAD) ssrf protectionflowisebypasstoctou https://advisories.gitlab.com/npm/openclaw/CVE-2026-32043/ OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host | GitLab Advisory... CVE-2026-32043 OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host: In openclaw@2026.2.24, approval-bound system.run on node... https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35364/ uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database... CVE-2026-35364 uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition: A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the... https://codeql.github.com/codeql-standard-libraries/actions/codeql/actions/security/ControlChecks.qll/predicate.ControlChecks$non_toctou_category.0.html non_toctou_category API documentation for CodeQL nontoctoucategory https://advisories.gitlab.com/maven/org.apache.tomcat.embed/tomcat-embed-core/CVE-2022-23181/ Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database (GLAD) CVE-2022-23181 Time-of-check Time-of-use (TOCTOU) Race Condition: The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into... race conditiontimecheckusetoctou https://aws.amazon.com/security/security-bulletins/rss/2026-025-aws/ CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight... https://advisories.gitlab.com/npm/openclaw/CVE-2026-43529/ OpenClaw: TOCTOU read in exec script preflight | GitLab Advisory Database (GLAD) CVE-2026-43529 OpenClaw: TOCTOU read in exec script preflight: OpenClaw's exec script preflight validator previously validated and then read a script by... openclawtoctoureadexec https://advisories.gitlab.com/nuget/magick.net-q8-anycpu/CVE-2026-28689/ ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD) CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap... https://advisories.gitlab.com/composer/magento/community-edition/CVE-2025-24430/ Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory Database... CVE-2025-24430 Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10,... https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35356/ uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition | GitLab Advisory... CVE-2026-35356 uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition: A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the... https://advisories.gitlab.com/pypi/pywbem/CVE-2013-6444/ PyWBEM TOCTOU vulnerability in certificate validation | GitLab Advisory Database (GLAD) CVE-2013-6444 PyWBEM TOCTOU vulnerability in certificate validation: PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in... certificate validationtoctouvulnerabilitygitlabadvisory https://advisories.gitlab.com/golang/github.com/buildkite/elastic-ci-stack-for-aws/v6/CVE-2023-43741/ Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database (GLAD) CVE-2023-43741 Time-of-check Time-of-use (TOCTOU) Race Condition: A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS... race conditiontimecheckusetoctou https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35376/ uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database... CVE-2026-35376 uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition: A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the... https://advisories.gitlab.com/pypi/virtualenv/CVE-2026-22702/ virtualenv Has TOCTOU Vulnerabilities in Directory Creation | GitLab Advisory Database (GLAD) CVE-2026-22702 virtualenv Has TOCTOU Vulnerabilities in Directory Creation: TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local... virtualenvtoctouvulnerabilities https://advisories.gitlab.com/nuget/magick.net-q8-x64/CVE-2026-28689/ ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD) CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap... https://advisories.gitlab.com/nuget/magick.net-q8-openmp-arm64/CVE-2026-28689/ ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD) CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap... https://advisories.gitlab.com/maven/org.apache.tomcat/tomcat-catalina/CVE-2024-50379/ Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory... CVE-2024-50379 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability... apache tomcat https://advisories.gitlab.com/composer/magento/project-community-edition/CVE-2025-49558/ Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory Database... CVE-2025-49558 Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Magento versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11,... https://dev.to/piiiico/toctou-of-trust-why-agent-governance-must-be-continuous-40ma TOCTOU of Trust: Why Agent Governance Must Be Continuous - DEV Community Three breaches, one shape In early April 2026, three separate tools that millions of... Tagged with agents, trust, mcp, security. agent governancemust betoctoutrust https://advisories.gitlab.com/maven/org.apache.tomcat/tomcat-catalina/CVE-2024-56337/ Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory... CVE-2024-56337 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability... apache tomcat https://advisories.gitlab.com/nuget/magick.net-q16-hdri-x64/CVE-2026-28689/ ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD) CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap... https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35353/ uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database... CVE-2026-35353 uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition: The mkdir utility in uutils coreutils incorrectly applies permissions... https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35374/ uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | GitLab Advisory Database... CVE-2026-35374 uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition: A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the... https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-34368/ AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance |... CVE-2026-34368 AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance: The transferBalance() method in... https://es.mathworks.com/help/bugfinder/ref/certcrulefio45c.html CERT C: Rule FIO45-C - Avoid TOCTOU race conditions while accessing files - MATLAB Avoid TOCTOU race conditions while accessing files. https://advisories.gitlab.com/nuget/magick.net-q16-hdri-openmp-x64/CVE-2026-28689/ ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD) CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap... https://groups.google.com/g/kubernetes-security-announce/c/-MFX60_wdOY [Security Advisory] CVE-2020-8562: Bypass of Kubernetes API Server proxy TOCTOU security advisory https://nl.mathworks.com/help/bugfinder/ref/cwe367.html CWE Rule 367 - Time-of-check Time-of-use (TOCTOU) Race Condition - MATLAB The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that... race conditioncweruletime https://advisories.gitlab.com/cargo/coreutils/CVE-2026-35354/ uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition | GitLab Advisory... CVE-2026-35354 uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition: A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the... https://advisories.gitlab.com/npm/openclaw/CVE-2026-41296/ OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile | GitLab Advisory Database... CVE-2026-41296 OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile: Sandbox escape via TOCTOU race in remote FS bridge readFile https://advisories.gitlab.com/cargo/remove_dir_all/GHSA-mc8h-8q98-g5hr/ Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in... GHSA-mc8h-8q98-g5hr Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all: The remove_dir_all crate is... race condition https://advisories.gitlab.com/composer/magento/community-edition/CVE-2025-24432/ Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | GitLab Advisory Database... CVE-2025-24432 Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability: Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10,... https://advisories.gitlab.com/nuget/magick.net-q16-x86/CVE-2026-28689/ ImageMagick has a Path Policy TOCTOU symlink race bypass | GitLab Advisory Database (GLAD) CVE-2026-28689 ImageMagick has a Path Policy TOCTOU symlink race bypass: domain="path" authorization is checked before final file open/use. A symlink swap...