SSRF Beyond HTTP: Egress-Path-Incomplete Guards in AI Agent Platforms
A formal egress-path-incomplete SSRF model instantiated on CVE-2026-33234 (AutoGPT). Zenodo, 2026.
I research vulnerabilities and drive coordinated disclosure. Two published papers with DOIs, 17 CVEs credited by Apple, CISA, the NSA, and NASA, and an M.S. in Cybersecurity from Pace University. This is the research and the receipts.
Seventeen published CVEs, sandbox escapes, SSRF, auth bypass, IDOR, path traversal, and DoS across Apple, NSA, CISA, NASA, AutoGPT, yt-dlp, and BlueprintUE.
Full technical write-ups, reproduction scripts, and per-CVE evidence live on the technical hub, pavanchow.github.io. Every credential is mapped to its independent source on the verification page.
Reproduction scripts for disclosed vulnerabilities. A random PoC is loaded on each visit. Click a tab to switch.
Open-access security research preprints with permanent DOIs, indexed by OpenAIRE.
A formal egress-path-incomplete SSRF model instantiated on CVE-2026-33234 (AutoGPT). Zenodo, 2026.
File-write attacks from attacker-controlled archive and download metadata across three 2026 CVEs. Zenodo, 2026.
A static detector for positional permission gaps (the confused-deputy pattern) in AI agent workflows, evaluated by rediscovering four upstream-fixed SSRF CVEs as an independent oracle. Preprints.org, 2026.
Seeding ML-KEM (FIPS-203) from a CHSH-certified quantum source in the QROM. A random-oracle hash carries quantum-conditional min-entropy into IND-CCA security at a one-way-to-hiding loss with no extractor, and classical randomness certificates are shown insufficient. IACR ePrint, 2026.
Benchmarking and analysis of post-quantum cryptography algorithms on constrained IoT hardware. Pace University CYB691 capstone with Ravindra Dholariya.
Independent databases, vendors, government agencies, security media, and community that track, credit, and feature this work. Every link points to the source that carries the credit.
Credits Pavan Nallamothu for CVE-2026-50023 in yt-dlp. Surfaced automatically inside enterprise dependency scans worldwide.
Credited in ICSA-26-230-01 for CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177 in CISA Malcolm.
Credited in Apple's macOS security release notes for CVE-2026-43763 in Apple Type Services.
Credited reporter on the GitHub-reviewed advisory for the yt-dlp filename bug, GHSA-c6mh-fpjc-4pr3.
Google's open vulnerability database mirrors the credited advisories into automated supply-chain tooling.
Apple's advisory APPLE-SA-07-27-2026-3 on the Full-Disclosure mailing list credits Pavan Nallamothu by name for CVE-2026-43763.
Independent coverage of CISA ICSA-26-230-01 that credits pavanchow among the researchers who reported the Malcolm findings.
Independent write-up naming pavanchow as the reporter of CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177 to CISA.
First non-government site to credit pavanchow for the CISA Malcolm advisory ICSA-26-230-01.
Featured as a SECON NJ 2024 organizer and speaker on Zero Trust, with a full-name researcher bio in the chapter newsletter.
Credits Pavan Nallamothu for CVE-2026-65412, a null pointer dereference in CoreText reachable by processing web content, and separately names him under Additional recognition for Foundation in the same release.
Independent coverage of every security fix in iOS 27 and iPadOS 27 that carries Apple's credit lines verbatim, including the CVE-2026-65412 CoreText entry and the Foundation acknowledgment.
The project's own SECURITY.md names Pavan Nallamothu in section 13, Acknowledgments, for one advisory. The disclosure record held by the maintainers themselves.
Apple's macOS Sonoma 14.8.8 advisory on the Full-Disclosure list credits Pavan Nallamothu and Jared Reyes for CVE-2026-43763, a sandbox file-read in Apple Type Services.
A long-running archive of vulnerabilities, advisories, and exploits. File entry 230694.
Credits Pavan Nallamothu in the AIT-Core security advisory for a format-string memory exhaustion in the BSC capture manager, reachable through an unvalidated file name pattern and capable of crashing the ground station capture manager. Fixed in 3.1.2.
From operating AWS infrastructure at scale to authoring CTF challenges and providing campus IT support.
M.S. Cybersecurity from Pace University with Graduate Merit Scholarship.
Pace University, New York, NY · 2023 - 2025 · Graduate Merit Scholarship
Speaking, mentoring, competing, and organizing in the security and open-source communities.
Security tooling plus academic and personal builds, and long-form writing and experiments across the site.
Python app that pulls job postings from TimesJobs, applying secure data-handling and network-defense concepts.
Embeds sensitive data inside video files using the Forbidden Zone Data Hiding technique, preserving confidentiality and integrity.
"Follow But No Track", methods to publish social-network user profiles while preserving user privacy.
A Python tool demonstrating the double transposition encryption process with a step-by-step educational breakdown.
A Python utility for fast text search across local directories on Linux, showcasing filesystem management.
A Bash script that logs public network addresses for simple, continuous network monitoring.
Type help to see all commands. Try neofetch, cves, experience, or scan github.com.
Open to collaboration, responsible-disclosure coordination, and security conversations.
Have a question or want to work together? Reach out directly.
Just kidding. But you did type the Konami Code!