I have successfully identified and reported multiple security vulnerabilities in open-source projects, including Apache Thrift and TDengine.
| Vulnerability | Type | Status | Reference | CVE |
|---|---|---|---|---|
| ZLIB Heap-based Buffer Overflow | Critical (9.3/10) | Accepted/Published | CVE-2026-55971 | CVE-2026-55971 |
| Integer Overflow | High (8.7/10) | Accepted/Published | CVE-2026-55969 | CVE-2026-55969 |
| Heap Out-of-Bounds Read | Medium (6.9/10) | Accepted/Published | CVE-2026-55970 | CVE-2026-55970 |
| Vulnerability | Type | Status | Reference | CVE |
|---|---|---|---|---|
| Off-by-One Buffer Overflow | High (8.3/10) | Accepted/Published | GHSA-4v5h-fxjw-vrmq | CVE-2026-62349 |
| Unauthenticated Remote DoS | High (7.5/10) | Accepted/Published | GHSA-8pc4-p252-f5m7 | CVE-2026-62351 |
| SQL Lexer OOB Read | Moderate (5.4/10) | Accepted/Published | GHSA-5r9p-3j4f-gmgp | CVE-2026-62353 |