π‘οΈ Application Security & Vulnerability Researcher
π SECURE CODE REVIEW Β Β π‘οΈ VULNERABILITY RESEARCH Β Β π€ AI/ML MODEL FILE VULNS
| CVE ID | Advisory | CVSS | Project | Summary | MITRE / NVD |
|---|---|---|---|---|---|
| CVE-2025-59420 | GHSA-9ggr-2464-2j32 | JWT/JWS accepts unknown crit headers β possible authz bypass |
nvd.nist.gov/vuln/detail/CVE-2025-59420 | ||
| CVE-2025-61920 | GHSA-pq5p-34cr-23v9 | DoS via oversized JOSE segments | nvd.nist.gov/vuln/detail/CVE-2025-61920 | ||
| CVE-2025-62706 | GHSA-g7f3-828f-7h7m | zip=DEF decompression bomb enables DoS |
nvd.nist.gov/vuln/detail/CVE-2025-62706 |
| Project | Description | Version | Link |
|---|---|---|---|
Fixed bug: b64 header ignored in unprotected header (now rejected). |
PR #210 | ||
| Collaborated on patch for critical header validation bypass. | PR #823 |