// root@pavan ~ ./research

Pavan Nallamothu

I research vulnerabilities and drive coordinated disclosure. Two published papers with DOIs, 17 CVEs credited by Apple, CISA, the NSA, and NASA, and an M.S. in Cybersecurity from Pace University. This is the research and the receipts.

📍 Jersey City, NJ 🎓 M.S. Cybersecurity · Pace University 🛡️ ISC² NJ Chapter · CTF Committee
Pavan Nallamothu, security researcher
17
CVEs Published
4
Apple · CISA · NSA · NASA
5
Disclosure Platforms
4+
Years Cloud/DevOps

CVE Portfolio

Seventeen published CVEs, sandbox escapes, SSRF, auth bypass, IDOR, path traversal, and DoS across Apple, NSA, CISA, NASA, AutoGPT, yt-dlp, and BlueprintUE.

Full technical write-ups, reproduction scripts, and per-CVE evidence live on the technical hub, pavanchow.github.io. Every credential is mapped to its independent source on the verification page.

// hover to pause, swipe to browse on mobile

From the Lab

Reproduction scripts for disclosed vulnerabilities. A random PoC is loaded on each visit. Click a tab to switch.

pavan@lab: ~

Publications

Open-access security research preprints with permanent DOIs, indexed by OpenAIRE.

Preprint

SSRF Beyond HTTP: Egress-Path-Incomplete Guards in AI Agent Platforms

A formal egress-path-incomplete SSRF model instantiated on CVE-2026-33234 (AutoGPT). Zenodo, 2026.

Preprint

Trusting the Filename: File-Write Attacks from Untrusted Archive and Download Metadata

File-write attacks from attacker-controlled archive and download metadata across three 2026 CVEs. Zenodo, 2026.

Preprint · under review

Dominating the Deputy: Toward Positional Permission Completeness in Agentic Workflows

A static detector for positional permission gaps (the confused-deputy pattern) in AI agent workflows, evaluated by rediscovering four upstream-fixed SSRF CVEs as an independent oracle. Preprints.org, 2026.

Preprints.orgunder review · DOI on approval
Preprint · under review

Composable Seeding of ML-KEM from Certified Bell Randomness in the QROM

Seeding ML-KEM (FIPS-203) from a CHSH-certified quantum source in the QROM. A random-oracle hash carries quantum-conditional min-entropy into IND-CCA security at a one-way-to-hiding loss with no extractor, and classical randomness certificates are shown insufficient. IACR ePrint, 2026.

IACR ePrintunder review · link on approval
M.S. Capstone · 2025

Post-Quantum Cryptography for Resource-Constrained IoT Devices

Benchmarking and analysis of post-quantum cryptography algorithms on constrained IoT hardware. Pace University CYB691 capstone with Ravindra Dholariya.

Pace UniversityCode & paper →

Recognition

Independent databases, vendors, government agencies, security media, and community that track, credit, and feature this work. Every link points to the source that carries the credit.

Commercial scanner

Snyk Vulnerability Database

Credits Pavan Nallamothu for CVE-2026-50023 in yt-dlp. Surfaced automatically inside enterprise dependency scans worldwide.

Government

CISA ICS Advisory

Credited in ICSA-26-230-01 for CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177 in CISA Malcolm.

Vendor

Apple Security Updates

Credited in Apple's macOS security release notes for CVE-2026-43763 in Apple Type Services.

Dev ecosystem

GitHub Security Advisories

Credited reporter on the GitHub-reviewed advisory for the yt-dlp filename bug, GHSA-c6mh-fpjc-4pr3.

Open database

OSV.dev

Google's open vulnerability database mirrors the credited advisories into automated supply-chain tooling.

Disclosure list

Full-Disclosure

Apple's advisory APPLE-SA-07-27-2026-3 on the Full-Disclosure mailing list credits Pavan Nallamothu by name for CVE-2026-43763.

Security media

OT Security Wire

Independent coverage of CISA ICSA-26-230-01 that credits pavanchow among the researchers who reported the Malcolm findings.

OT Security WireRead →
Security media

CyberICT

Independent write-up naming pavanchow as the reporter of CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177 to CISA.

CyberICTRead →
Independent

Assurant Cyber

First non-government site to credit pavanchow for the CISA Malcolm advisory ICSA-26-230-01.

Assurant CyberRead →
Speaking

ISC2 NJ Chapter

Featured as a SECON NJ 2024 organizer and speaker on Zero Trust, with a full-name researcher bio in the chapter newsletter.

Vendor

Apple: iOS 27 and iPadOS 27

Credits Pavan Nallamothu for CVE-2026-65412, a null pointer dereference in CoreText reachable by processing web content, and separately names him under Additional recognition for Foundation in the same release.

Security media

9to5Mac

Independent coverage of every security fix in iOS 27 and iPadOS 27 that carries Apple's credit lines verbatim, including the CVE-2026-65412 CoreText entry and the Foundation acknowledgment.

9to5MacRead →
Project record

AutoGPT Security Policy

The project's own SECURITY.md names Pavan Nallamothu in section 13, Acknowledgments, for one advisory. The disclosure record held by the maintainers themselves.

Disclosure list

Full-Disclosure: APPLE-SA-07-27-2026-4

Apple's macOS Sonoma 14.8.8 advisory on the Full-Disclosure list credits Pavan Nallamothu and Jared Reyes for CVE-2026-43763, a sandbox file-read in Apple Type Services.

Security archive

Packet Storm

A long-running archive of vulnerabilities, advisories, and exploits. File entry 230694.

Packet StormFile 230694 →
Government agency

NASA Advanced Multi-Mission Operations System

Credits Pavan Nallamothu in the AIT-Core security advisory for a format-string memory exhaustion in the BSC capture manager, reachable through an unvalidated file name pattern and capable of crashing the ground station capture manager. Fixed in 3.1.2.

Professional Experience

From operating AWS infrastructure at scale to authoring CTF challenges and providing campus IT support.

Education & Certifications

M.S. Cybersecurity from Pace University with Graduate Merit Scholarship.

Education

M.S. Cybersecurity

Pace University, New York, NY · 2023 - 2025 · Graduate Merit Scholarship

Certifications

Community & Activities

Speaking, mentoring, competing, and organizing in the security and open-source communities.

Projects & Writing

Security tooling plus academic and personal builds, and long-form writing and experiments across the site.

Academic

Jobs Web Scraper

Python app that pulls job postings from TimesJobs, applying secure data-handling and network-defense concepts.

Academic

Robust Video Data Hiding

Embeds sensitive data inside video files using the Forbidden Zone Data Hiding technique, preserving confidentiality and integrity.

SteganographyResearch →
Academic

Cyber-Physical Social System

"Follow But No Track", methods to publish social-network user profiles while preserving user privacy.

PrivacyResearch →
Personal

Double Transposition Cipher

A Python tool demonstrating the double transposition encryption process with a step-by-step educational breakdown.

Python · CryptoTool →
Personal

Local Search Engine

A Python utility for fast text search across local directories on Linux, showcasing filesystem management.

PythonTool →
Personal

IP Logger

A Bash script that logs public network addresses for simple, continuous network monitoring.

BashTool →

More from the site

Terminal

Type help to see all commands. Try neofetch, cves, experience, or scan github.com.

guest@pavan-blog: ~
guest@pavan-blog:~$

Contact

Open to collaboration, responsible-disclosure coordination, and security conversations.

Get in touch

Have a question or want to work together? Reach out directly.

Copied

SYSTEM BREACH DETECTED

Just kidding. But you did type the Konami Code!