Trusting the Wrong Length: Anatomy of a Pre-Auth Gateway RCE
A full walk-through of CVE-2026-31884: how a single trusted length field in a TLS resumption parser became a reliable remote root, and the heap-grooming that made the exploit stable across appliance builds.