- π¨βπ» All of my projects are available at https://github.com/herdiyana256
- π¬ Ask me about Web Security, Android Dev, DevSecOps, CI/CD Pipeline Security, Automation
- π« How to reach me herdiyan@supernesia.id
- π¨βπ» My Business Supernesia Creative Technology
| Organization | Finding | Platform | Year |
|---|---|---|---|
| π¬ Google OSS VRP (osv-scalibr) | Fixed os/rpm extractor to map AlmaLinux ecosystem β previously zero ALSA advisories detected across 1B+ pulled AlmaLinux container images. (PR #2148) |
Google OSS VRP (PRP) | 2026 |
| π¬ Google OSS VRP (osv-scalibr) | Fixed os/rpm extractor to map Mageia ecosystem β previously zero MGASA advisories detected across 5,900+ tracked Mageia OSV.dev entries. (PR #2199) |
Google OSS VRP (PRP) | 2026 |
| π Angular CLI (build-angular) | OS command injection hardening in SSR dev server builder outputPath from angular.json was interpolated into a shell string with shell: true, allowing $() command substitution. Fixed via 3-arg spawn() (PR #33479). Classified by maintainers as hardening, not a vulnerability. |
Google OSS VRP | 2026 |
| βοΈ Nextcloud | OCS Share API exposes full Argon2id password hash of password-protected link shares via /ocs/v2.php/apps/files_sharing/api/v1/shares, enabling offline brute-force attacks without rate limiting. |
YesWeHack | 2026 |
| π Keycloak | Cross-client token introspection IDOR via /realms/{realm}/protocol/openid-connect/token/introspect any confidential OAuth client can introspect tokens issued to other clients, leaking full PII and session metadata (username, email, sub, roles, session state) without authorization. Fixed in Keycloak 26.6.3. (CVE-2026-37979) |
YesWeHack | 2026 |
| πΉ Go (golang/x/image) | VP8L decoder validation-ordering flaw β dimension check ran after a 1 GiB allocation instead of before. Credited by the Go team in golang/go#80063; fix landed in CL 792240. Classified as a hardening measure. | Google OSS VRP | 2026 |
| π¬ Google OSS VRP (osv-scanner) | Enabled Swift PackageResolved plugin to detect SwiftURL ecosystem CVEs β fixing zero CVE matches for SPM packages previously misidentified as CocoaPods (PR #2801) | Google OSS VRP | 2026 |
| π¬ Google OSS VRP (osv-scalibr) | Ecosystem misclassification fix causing zero CVE matches for Wolfi OS and Chainguard container images | Google OSS VRP | 2026 |
| π NASA (globe.gov) | Information Disclosure on official government platform | Bugcrowd VDP | 2026 |
| π Google OSS VRP (Angular) | Critical vulnerability in CI/CD pipeline affecting widely used open source project | Google OSS VRP | 2026 |
| π OpenProject | Improper Access Control leading to unauthorized cross-project data manipulation (CVE-2026-27722 Β· GHSA-xw8w-4qxm-g9gv) | YesWeHack | 2026 |
| π OpenProject | Authentication logic flaw enabling account compromise | YesWeHack | 2026 |
| π OpenProject | Improper Access Control on sensitive reporting module | YesWeHack | 2026 |
| π³ PayPal | Business Logic vulnerability in payment processing workflow | HackerOne | 2026 |
| π¨ Shiji Group | Broken Access Control on enterprise hospitality management platform | YesWeHack | 2026 |
| π° Geenius Meedia | Multiple Business Logic vulnerabilities across subscription and content delivery systems | YesWeHack | 2026 |
| π§ cURL | Functional regression in core authentication implementation | HackerOne | 2026 |
| π― YesWeHack Dojo #49 | Challenge Winner β exploitation chain achieving restricted file access | YesWeHack Dojo | 2026 |
| π― YesWeHack Dojo #50 | Challenge Winner β bypass of security controls with bonus points awarded | YesWeHack Dojo | 2026 |



