- π¨βπ» All of my projects are available at https://github.com/herdiyana256
- π¬ Ask me about Web Security, Android Dev, DevSecOps, CI/CD Pipeline Security, Automation
- π« How to reach me herdiyan@supernesia.id
- π¨βπ» My Business Supernesia Creative Technology
| Organization | Finding | Platform | Year |
|---|---|---|---|
| π¦ Easyship | Exposed Addressy (Loqate) API key in client-side JS bundle with no domain restriction, enabling unauthorized quota-draining API abuse (CWE-798) | YesWeHack | 2026 |
| π¬ Google OSS VRP (osv-scalibr) | Fixed os/rpm extractor to map AlmaLinux ecosystem previously zero ALSA advisories detected across 1B+ pulled AlmaLinux container images. (PR #2148) |
Google OSS VRP (PRP) | 2026 |
| π¬ Google OSS VRP (osv-scalibr) | Fixed os/rpm extractor to map Mageia ecosystem previously zero MGASA advisories detected across 5,900+ tracked Mageia OSV.dev entries. (PR #2199) |
Google OSS VRP (PRP) | 2026 |
| π¬ Google OSS VRP (osv-scalibr) | Fixed os/rpm extractor to map the openSUSE Leap ecosystem container scans previously returned zero advisories because the openSUSE OSID went unhandled. (PR #2290) |
Google OSS VRP (PRP) | 2026 |
| π¬ Google OSS VRP (osv-scanner) | Added end-to-end test coverage for openSUSE Leap ecosystem mapping in osv-scanner, locking in the fix downstream. (PR #2937) | Google OSS VRP (PRP) | 2026 |
| π Angular CLI (build-angular) | OS command injection hardening in SSR dev server builder outputPath from angular.json was interpolated into a shell string with shell: true, allowing $() command substitution. Fixed via 3-arg spawn() (PR #33479). Classified by maintainers as hardening, not a vulnerability. |
Google OSS VRP | 2026 |
| π€ Google ADK (adk-python) | Redacted the database password from DatabaseSessionService engine-creation errors and session-migration logs β a networked connection URI leaked its password verbatim into exceptions and logs (CWE-532). Fix extended by maintainers to query-parameter secrets and four further migration log sites. (PR #6485, merged via Copybara) |
Google OSS VRP | 2026 |
| βοΈ Google OSS VRP (go-cloud) | A batch of merged security-hardening fixes across go-cloud cloud drivers: Vault API path traversal in secrets/hashivault and runtimevar/hashivault (CWE-22/863, #3763/#3764), SNS-envelope forgery in pubsub/awssnssqs (CWE-345, #3762), credential-in-error leaks in the Postgres/MySQL drivers (CWE-532, #3752/#3753), a cleartext-password auth downgrade (#3761), and unrecovered-panic DoS in docstore/awsdynamodb (#3754/#3760). |
Google OSS VRP | 2026 |
| βοΈ Nextcloud | OCS Share API exposes full Argon2id password hash of password-protected link shares via /ocs/v2.php/apps/files_sharing/api/v1/shares, enabling offline brute-force attacks without rate limiting. |
YesWeHack | 2026 |
| π Keycloak | Cross-client token introspection IDOR via /realms/{realm}/protocol/openid-connect/token/introspect any confidential OAuth client can introspect tokens issued to other clients, leaking full PII and session metadata (username, email, sub, roles, session state) without authorization. Fixed in Keycloak 26.6.3. (CVE-2026-37979) |
YesWeHack | 2026 |
| πΉ Go (golang/x/image) | VP8L decoder validation-ordering flaw β dimension check ran after a 1 GiB allocation instead of before. Credited by the Go team in golang/go#80063; fix landed in CL 792240. Classified as a hardening measure. | Google OSS VRP | 2026 |
| π¬ Google OSS VRP (osv-scanner) | Enabled Swift PackageResolved plugin to detect SwiftURL ecosystem CVEs β fixing zero CVE matches for SPM packages previously misidentified as CocoaPods (PR #2801) | Google OSS VRP | 2026 |
| π¬ Google OSS VRP (osv-scalibr) | Ecosystem misclassification fix causing zero CVE matches for Wolfi OS and Chainguard container images | Google OSS VRP | 2026 |
| π NASA (globe.gov) | Information Disclosure on official government platform | Bugcrowd VDP | 2026 |
| π Google OSS VRP (Angular) | Critical vulnerability in CI/CD pipeline affecting widely used open source project | Google OSS VRP | 2026 |
| π OpenProject | Improper Access Control leading to unauthorized cross-project data manipulation (CVE-2026-27722 Β· GHSA-xw8w-4qxm-g9gv) | YesWeHack | 2026 |
| π OpenProject | Authentication logic flaw enabling account compromise | YesWeHack | 2026 |
| π OpenProject | Improper Access Control on sensitive reporting module | YesWeHack | 2026 |
| π³ PayPal | Business Logic vulnerability in payment processing workflow | HackerOne | 2026 |
| π¨ Shiji Group | Broken Access Control on enterprise hospitality management platform | YesWeHack | 2026 |
| π° Geenius Meedia | Multiple Business Logic vulnerabilities across subscription and content delivery systems | YesWeHack | 2026 |
| π§ cURL | Functional regression in core authentication implementation | HackerOne | 2026 |
| π― YesWeHack Dojo #49 | Challenge Winner β exploitation chain achieving restricted file access | YesWeHack Dojo | 2026 |
| π― YesWeHack Dojo #50 | Challenge Winner β bypass of security controls with bonus points awarded | YesWeHack Dojo | 2026 |



