CVE-2025-21756Linux kernel use-after-free in the vsock subsystem — fix auto-merged 11 hours before public disclosure, blocking the exploit chain on patched hosts.
Read case studyCVE remediation
Every CVE ZeroPatch auto-patched before public disclosure — the full writeup for each advisory, from dependency graph detection through merged PR.
CVE-2025-21756Linux kernel use-after-free in the vsock subsystem — fix auto-merged 11 hours before public disclosure, blocking the exploit chain on patched hosts.
Read case studyCVE-2025-24201React Server Components deserialization flaw allowing boundary bypass — patch propagated to 14 downstream apps before the advisory went public.
Read case studyCVE-2025-23114OpenSSL XLLO handshake state-machine defect — zeroPatch PR accepted upstream and rolled into 6 vendor LTS branches during the embargo window.
Read case studyCVE-2025-22869Next.js middleware token-validation regression — surface patched across staging ahead of disclosure, no customer interrupt.
Read case studyCVE-2025-22091curl URL parser parser-confusion bug on percent-encoded NUL bytes — tracked fix merged into our deployment pin the same day.
Read case study