moltenbit

Security Research

36 disclosures 30 CVEs last update 2026-07-30

Security vulnerabilities I have responsibly disclosed. All findings were reported to the affected vendors and patched before public disclosure.

Disclosure ledger / 36

2026
CVE-2026-46647
GlobaLeaks

insufficient role enforcement allows non-admin internal users on the root or management tenant to read and modify network configuration

No CVE
vinext

Authentication bypass via i18n locale prefix; middleware matcher evaluates unsanitized pathname

No CVE
vinext

Middleware header sanitization bypass; missing x-middleware-override-headers allows header spoofing

CVE-2026-58418
Gitea

SSRF via HTTP redirect in repository migration allows authenticated users to bypass internal address restrictions and reach localhost or private-network services

No CVE
Hushline

IDOR in FieldDefinition lets authenticated users alter or destroy other users’ submission fields and stored disclosure content

2025

Hall of fame

HackerOne

Ranked among the top contributors of the program.