researcher@authorized-scope:~$ list ./findings

Bug Bounty Research

Sanitized technical reports from authorized security testing. Target identity, report identifiers and tenant-specific details are intentionally withheld; methodology, evidence boundaries and triage outcomes remain transparent.

3 documented findings Authorized scope Sanitized disclosure

Disclosure archive

From technical signal to triage outcome

Each article separates the verified behavior, reproducible evidence, practical impact, limitations and final program decision.

Informative — Closed

Blind SSRF / DNS validation bypass

DNS-Resolved Private Address Bypass in a Server-Side JWKS Fetcher

A controlled callback and timing analysis showed that a hostname resolving to RFC1918 space reached a backend fetch stage, with impact limited to blind reconnaissance.

Severity
Medium
Testing
Authorized
Read the finding

Publication standard

Technical detail without exposing the target

Evidence over claims

Observed timings, response classes and controlled callbacks are distinguished from impact that was not demonstrated.

Sanitized disclosure

The target, domains, report IDs, tenant identifiers, credentials and private program details are not published.

Authorized testing

Validation used owned accounts and projects, low request volumes and non-destructive techniques within published scope.