Case studies

Recent CVE fixes

The 5 most recent advisories ZeroPatch auto-merged a fix for — what was patched, when, and which library it landed in. Each entry links through to the live audit log for the full diff and timeline.

  1. Critical
    CVE-2025-21756

    Linux kernel use-after-free in the vsock subsystem — fix auto-merged 11 hours before public disclosure, blocking the exploit chain on patched hosts.

    Read case study
  2. High
    CVE-2025-24201

    React Server Components deserialization flaw allowing boundary bypass — patch propagated to 14 downstream apps before the advisory went public.

    Read case study
  3. Critical
    CVE-2025-23114

    OpenSSL XLLO handshake state-machine defect — zeroPatch PR accepted upstream and rolled into 6 vendor LTS branches during the embargo window.

    Read case study
  4. High
    CVE-2025-22869

    Next.js middleware token-validation regression — surface patched across staging ahead of disclosure, no customer interrupt.

    Read case study
  5. Medium
    CVE-2025-22091

    curl URL parser parser-confusion bug on percent-encoded NUL bytes —tracked fix merged into our deployment pin the same day.

    Read case study