whoami
field notes
- CVE
18798 double free in openssl's quic channel bind path · CVE-2026-18798 · cve, openssl, quic, c · 6 min a pointer in OpenSSL's QUIC bind path does double duty as a return value and an ownership handoff. when a bind fails, it's left unwritten, so the caller assumes the channel never took the QRX and frees it again after the channel already did. fixed in 3.5.8 / 3.6.4 / 4.0.2. - CVE
25087 signed overflow in arrow's ipc reader · CVE-2026-25087 · cve, fuzzing, apache-arrow, c++ · 3 min the "prebuffered" read path had zero fuzz coverage, and theCoalesceReadRanges()function didn't check whether offset + length overflows int64. fixed in PR #48925.
journal
- nothing posted yet.
disclosures
elsewhere
settings
whoami
emilloc. adversarial operator @Bishop Fox. focused on vulnerability research, reverse engineering, and AI x security, bug bounty on the side.
i find and disclose vulns in open-source and enterprise software (CVE-2026-18798, CVE-2026-25087, CVE-2026-9087), built snowpick to hunt public data exposure in ServiceNow, and have multiple acknowledgements from Apple's web server security team.
DISCLAIMER: these are my field notes, written for me and public in case they're useful to others. they keep me honest and visible (plus they help me remember all the things i want to test, lol).
if you found this helpful, share it, and send tips my way.