Auto-merged fixes

Changelog

A chronological record of the CVE fixes ZeroPatch auto-merged before public disclosure, from first detection through a landed patch.

  1. CVE-2025-21756
    Critical

    Linux kernel use-after-free in the vsock subsystem — fix auto-merged 11 hours before public disclosure, blocking the exploit chain on patched hosts.

  2. CVE-2025-24201
    High

    React Server Components deserialization flaw allowing boundary bypass — patch propagated to 14 downstream apps before the advisory went public.

  3. CVE-2025-23114
    Critical

    OpenSSL XLLO handshake state-machine defect — zeroPatch PR accepted upstream and rolled into 6 vendor LTS branches during the embargo window.

  4. CVE-2025-22869
    High

    Next.js middleware token-validation regression — surface patched across staging ahead of disclosure, no customer interrupt.

  5. CVE-2025-22091
    Medium

    curl URL parser parser-confusion bug on percent-encoded NUL bytes —tracked fix merged into our deployment pin the same day.