security.
Vulnerability disclosures, personal security assessments, and public reports.
- disclosures since 2024
- 9
- highest CVSS
- 8.7
- CVE credited
- 1
- public reports
- 4
reports
disclosure log
Hono · 2026
Reported an XSS in hono/jsx server-side rendering, credited on CVE-2026-93981 and fixed in 4.13.7.
Fédération Française d'Athlétisme · 2026
Reported weak cryptographic practices and non-robust implementations.
libsoup · 2026
Reported a memory corruption issue in the HTTP client/server library.
Iliad / Freebox OS · 2026
Reported two vulnerabilities affecting Freebox OS, enabling one-click account takeover.
Santé Publique France · 2026
Reported an IDOR exposing personally identifiable data for roughly 250 EUR in bounty.
pdfcpu · 2025
Reported a stack overflow leading to denial of service.
React2Shell incident response · 2025
Validated exploitability on production applications managed by Galadrim and coordinated remediation with development teams.
Proton · 2025
Identified and reported an access control flaw allowing a paywall bypass.
X (Twitter) · 2024
Reported a web and mobile denial of service affecting private messages, with a 1120 USD bounty.