CVE remediation

Case studies

Every CVE ZeroPatch auto-patched before public disclosure — the full writeup for each advisory, from dependency graph detection through merged PR.

  1. Critical
    CVE-2025-21756

    Linux kernel use-after-free in the vsock subsystem — fix auto-merged 11 hours before public disclosure, blocking the exploit chain on patched hosts.

    Read case study
  2. High
    CVE-2025-24201

    React Server Components deserialization flaw allowing boundary bypass — patch propagated to 14 downstream apps before the advisory went public.

    Read case study
  3. Critical
    CVE-2025-23114

    OpenSSL XLLO handshake state-machine defect — zeroPatch PR accepted upstream and rolled into 6 vendor LTS branches during the embargo window.

    Read case study
  4. High
    CVE-2025-22869

    Next.js middleware token-validation regression — surface patched across staging ahead of disclosure, no customer interrupt.

    Read case study
  5. Medium
    CVE-2025-22091

    curl URL parser parser-confusion bug on percent-encoded NUL bytes — tracked fix merged into our deployment pin the same day.

    Read case study