The author details a personal experiment to find a medium-severity vulnerability in the open-source ActivityPub server 'snac2' to test the relevance of human vulnerability research. An unauthenticated denial-of-service flaw was discovered through fuzzing, highlighting that while automated tools are powerful, manual exploration can still yield results in real-world software.
Background
snac2 is a minimalistic, C-based ActivityPub server used by various Fediverse instances. The post explores the intersection of manual security research and the growing debate about AI's impact on vulnerability discovery.
- Source
- Lobsters
- Published
- Jul 20, 2026 at 03:04 PM
- Score
- 5.0 / 10