~/security-research

security.

Vulnerability disclosures, personal security assessments, and public reports.

disclosures since 2024
9
highest CVSS
8.7
CVE credited
1
public reports
4

reports

0-click RCE + ASLR bypass exploit chain (again) (Binary)

0 day · · sent
Not published yet.

0-click RCE + ASLR bypass exploit chain (Binary)

0 day · · contacted
Not published yet.

Gray-box backend penetration testing (Web)

pentest · · fixed

Mobile Application Black Box Assessment (Android)

pentest · · acknowledged

disclosure log

Hono · 2026

Reported an XSS in hono/jsx server-side rendering, credited on CVE-2026-93981 and fixed in 4.13.7.

CVSS 4.7 Medium

Fédération Française d'Athlétisme · 2026

Reported weak cryptographic practices and non-robust implementations.

CVSS 5.9 Medium

libsoup · 2026

Reported a memory corruption issue in the HTTP client/server library.

CVSS 6.9 Medium

Iliad / Freebox OS · 2026

Reported two vulnerabilities affecting Freebox OS, enabling one-click account takeover.

CVSS 8.7 High

Santé Publique France · 2026

Reported an IDOR exposing personally identifiable data for roughly 250 EUR in bounty.

CVSS 8.7 High

pdfcpu · 2025

Reported a stack overflow leading to denial of service.

CVSS 8.2 High

React2Shell incident response · 2025

Validated exploitability on production applications managed by Galadrim and coordinated remediation with development teams.

incident

Proton · 2025

Identified and reported an access control flaw allowing a paywall bypass.

CVSS 6.3 Medium

X (Twitter) · 2024

Reported a web and mobile denial of service affecting private messages, with a 1120 USD bounty.

CVSS 5.9 Medium