docx4j Denial of Service through Cyclic Style Inheritance (CVE-2026-53752)
A crafted DOCX containing a cycle in its w:basedOn style chain sends docx4j into uncontrolled recursion and ends with a StackOverflowError. This affects docx4j through 11.5.13 and was fixed in 11.5.14.
Read More
Windows 10 Japanese IME Bug leading to Denial of Service
I traced severe desktop lag to a Japanese IME Registry handle leak that left ctfmon.exe holding more than 104,000 handles. A zero-capability AppContainer reproduced it on Windows 10, and MSRC classified the finding as a product reliability bug.
Read More
HelloTalk Precise GPS Location Disclosure via Unencrypted Local Database (CVE-2020-25900)
An old finding from 2019; the CVE was requested in 2020, approved by MITRE in August 2023, and sat in RESERVED state since. I was busy with life and didn't get around to writing it, doing the responsible disclosure now.
Read More
BurgerEditor for baserCMS Directory Listing (CVE-2024-44807)
A short writeup for an old CVE I was credited on during my time at Sompo. I held onto this draft for a while due to life and NDA.
Read More
LA CTF 2024 Writeup
Been a long, long time since I last touched CTFs. It wasn't any official team by any means, so I had to do multiple categories by myself in the few hours limited weekend time I had for the CTF.
Read More
DLL Hijacking in Installers generated by Squirrel.Windows (CVE-2022-46330)
While bug hunting, I stumbled upon an open source repository which had been the cause of several of my bug bounty reports. This post goes into the details.
Read More