Vulnerability Researcher · Systems Security
I research vulnerabilities in systems software—native code, embedded and wireless stacks, and operating-system kernels. I apply the same reachability-and-invariant approach to AI-agent platforms and web products, carrying findings through controlled reproduction, coordinated disclosure, and patch verification.
CVE case archive · Linux upstream evidence · Dreamhack · Email
15 CVE case studies · 13 public attributions · 3 Linux mainline patches · 154 Pwnable solves
attack surface → reachability → broken invariant → controlled reproduction → disclosure → patch
Case-study and attribution counts are separate scopes. Public advisory identities: foxirain · Amemoyoi.
Memory safety, parser robustness, privilege boundaries, and upstream remediation are the core of my work.
I authored two CVE fixes and one separate verifier fix, all merged into Linux mainline.
- USB UAC1 · CVE-2026-31720 — Control-request length validation for a 4-byte stack OOB write · mainline fix
- PPP namespaces · CVE-2026-53075 — Capability validation against the target network namespace · mainline fix
- BPF verifier — Oversized access-size validation and regression coverage · mainline fix
- libpng · CVE-2026-33636 — ARM/AArch64 NEON palette expansion could read and write beyond a short row buffer.
- arduino-esp32 · CVE-2026-41429 — An attacker-controlled NBNS
name_lencaused an out-of-bounds read and stack overflow. - Apache NimBLE · CVE-2026-45815 — A truncated BLE ATT Read Multiple Variable response reached a remotely triggerable host assertion.
- PraisonAI · CVE-2026-47391 · CVE-2026-48168 — A public A2A request reached an LLM-selected
eval()tool; an untrusted fork branch name reached a privileged workflow shell. - Langflow · CVE-2026-9135 — ToolGuard dynamic
CodeInputvalidation bypass to stored Python execution. The private report is retained; no public researcher attribution is claimed.
Seven case studies across LinkAce, NamelessMC, OpenFGA, Caddy, and listmonk cover SSRF, private-data exposure, cache isolation, OAuth state, path normalization, and permission boundaries. Browse the complete archive.
Dreamhack · Amemoyoi · Long-form project record
- 154 Pwnable challenges solved across memory corruption, ROP/SROP, heap exploitation, glibc/FSOP, ARM/AArch64, and Linux kernel exploitation
- 4,901 Wargame points · reached the overall Top 300 during the project · 259 analysis, experiment, and troubleshooting records retained
- Progressed from user-space primitives to controlled kernel AAR/AAW and
credoverwrite in Dreamhack's educational environments
Historical activity snapshot: 176 total Wargame solves across 93 active days, Mar 2025–Jan 2026. The 154 figure above refers to Pwnable solves.
Supporting repositories for research triage, provenance, and reproducible validation: Adaptive OSS Vulnerability Harness · Kernel Codex Harness · Agent Security Company
I am interested in vulnerability research and systems security roles, including product and AI/agent security.
Email: hataegu0826@gmail.com

