← Back

Research

Vulnerabilities I've found and reported. This list grows over time.

Path Traversal in Grafana Loki

A path traversal vulnerability in Grafana Loki that could allow unauthorized file access.

Grafana Path Traversal
Zip Slip in NSA's Ghidra

A Zip Slip vulnerability in the Ghidra reverse engineering tool that could lead to arbitrary file writes during archive extraction.

NSA Ghidra Zip Slip
LDAP Wildcard Injection in Bouncy Castle

The LDAP certificate processing API in Bouncy Castle did not sanitize X.500 names for LDAP wildcards, potentially leading to information disclosure when processing unvetted certificates.

Bouncy Castle LDAP Injection Cryptography