Exception Serialization Patterns in OpenStack Nova: Theoretical RCE Risks and Lessons Learned
Theoretical RCE risks in OpenStack Nova’s exception serialization via oslo.messaging, with PoC scenarios and defense patterns.
Representative Foreword
The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.
This essay frames the entire site first. The posts on technical analysis, method, and governance all start from this same problem statement.

Detection, Method, Governance
Theoretical RCE risks in OpenStack Nova’s exception serialization via oslo.messaging, with PoC scenarios and defense patterns.
Technical analysis of CVE-2019-17570 deserialization RCE in Apache XML-RPC, with patch comparison and secure implementation guidance.