
实际成果不虚。 对 21 个 Go 包做了超过 8000 万次 grammar-based fuzzing,挖出两个 OOM: CVE-2026-33809(x/image/tiff) CVE-2026-33812(x/image/font/sfnt) 另外还有一条完整的 OEM 服务 0day 链:认证绕过 → SSRF → 目录注入 → BYOVD → SYSTEM。 macOS 发行平台也有两个问题被确认。
Post summary
The text announces the discovery of two CVE-2026‑33809 and CVE-2026‑33812 OOM vulnerabilities in Go packages, and outlines a potential OEM service exploit chain, but does not provide PoC, exploit code, active usage, or patch information.

