
实际成果不虚。 对 21 个 Go 包做了超过 8000 万次 grammar-based fuzzing,挖出两个 OOM: CVE-2026-33809(x/image/tiff) CVE-2026-33812(x/image/font/sfnt) 另外还有一条完整的 OEM 服务 0day 链:认证绕过 → SSRF → 目录注入 → BYOVD → SYSTEM。 macOS 发行平台也有两个问题被确认。
Post summary
The post announces the discovery of two out‑of‑memory bugs in Go image packages (CVE‑2026‑33809, CVE‑2026‑33812) through extensive fuzzing, and notes additional zero‑day exploitation chains and macOS platform issues.


