Research / Community / Competition

Achievements.

Research records / 05Individual records / 34

Notable vulnerability research

Findings disclosed through coordinated, evidence-driven research.

01 / 052026.08.25FreeBSD / ppp(8)Published

CVE-2026-58095

Global buffer overflow in ppp(8) endpoint discriminator formatting

An incorrect length calculation in mp_Enddisc() could allow a malicious PPP peer to overflow a global result buffer through a received multilink endpoint discriminator option.

Advisory
FreeBSD-SA-26:60.ppp
Credit
Reo Shiseki / n01e0
Affected
All supported FreeBSD versions at disclosure
FreeBSD Security Advisory
02 / 052026.08.25FreeBSD / ppp(8)Published

CVE-2026-58096

Out-of-bounds write in ppp(8) endpoint option decoding

Missing minimum-length validation in LcpDecodeConfig() could allow a malicious PPP peer to trigger an out-of-bounds write with an undersized multilink endpoint discriminator option.

Advisory
FreeBSD-SA-26:60.ppp
Credit
Reo Shiseki / n01e0
Affected
All supported FreeBSD versions at disclosure
FreeBSD Security Advisory
03 / 052026.08.25FreeBSD / ppp(8)Published

CVE-2026-58097

Buffer overflow in ppp(8) PSN endpoint handling

Missing length validation in mp_SetEnddisc() could allow a local user with access to the ppp(8) command interface to overflow a buffer through a user-supplied PSN endpoint value.

Advisory
FreeBSD-SA-26:60.ppp
Credit
Reo Shiseki / n01e0
Affected
All supported FreeBSD versions at disclosure
FreeBSD Security Advisory
04 / 052026.07.29FreeBSD / wg(4)Published

CVE-2026-58085

Missing MAC validation in wg(4) packet decryption

An authentication-validation flaw in the FreeBSD WireGuard driver that could allow forged or modified transport packets to be accepted under specific network conditions.

Advisory
FreeBSD-SA-26:52.if_wg
Credit
Reo Shiseki / n01e0
Affected
All supported FreeBSD versions at disclosure
FreeBSD Security Advisory
05 / 052026.07.15DifyPublished

GHSA-9c9q-5rj5-mjj2

Cross-Tenant File Preview via Unscoped Console file_id

An authenticated console user could retrieve another tenant's uploaded document preview when the file identifier was known because the preview path did not enforce tenant ownership.

Severity
High / 7.7
Affected
Dify <= 1.13.3
Patched
Dify 1.14.2
Credit
shukla304
GitHub Security Advisory
View all research records

Record / 2019 — 2026

Challenge design, instruction, speaking, community work, and competition results.

2026

2025

2024

2023

2022

2021

2020

2019