AB

Security engineering

Find the weak path.
Build the stronger one.

I investigate how modern systems fail, then turn those lessons into safer architecture, delivery, and operation.

Ahmedabad, India mapping / testing / correcting status: active

Research

Research that changed
real systems.

70+ Subdomains reviewed checked for weak points
3 Security bugs reported all fixed by the maintainers
CVE-2026-61549 Unrestricted workload identity in Kubernetes backend High · 7.5
pipeline YAMLserviceAccountNameprivileged pod identity
What was assumed
A pipeline author could safely choose any service account available in the namespace.
What could happen
A workload could run under a highly privileged, potentially cluster-admin, service account.
How it was fixed
Restrict service-account selection and apply least privilege at workload admission.
Status
PATCHED · 3.16.0
CVE-2026-40893 ExifTool dangerous-tag blocklist bypass High · 8.2
group-prefixed metadatablocklist mismatchdangerous tag accepted
What was assumed
Blocklisted tag names would always arrive in one canonical form.
What could happen
An attacker could influence file rename and move behavior during document processing.
How it was fixed
Normalize and validate group-prefixed tag names before evaluating the dangerous-tag policy.
Status
PATCHED · 8.31.0
CVE-2026-23603 Blind SSRF through OAuth2 avatar synchronization Low · 3.1
OIDC picture claimserver-side fetchinternal destination
What was assumed
The identity provider's picture claim was safe to fetch from the server network.
What could happen
A low-privileged user could trigger blind requests to otherwise unreachable internal URLs.
How it was fixed
Validate remote avatar destinations and constrain outbound fetch behavior.
Status
PATCHED · 1.27.0

Contact

Have a system worth
understanding deeply?

Start a conversation