Security
I'm Tom Ryan (A5omic), an independent security researcher. I find and report memory-safety and authorization flaws in widely used software. This page covers findings I reported or contributed to and separates confirmed public vulnerabilities from upstream bugs that were fixed but not classified as security vulnerabilities. Every named finding links to public proof. Reports still under coordinated disclosure stay generalized until the vendor publishes them.
Public record: three publicly documented security findings, one upstream bug fix, and one resolved report whose technical details remain private.
View @a5omic →Public vulnerabilities
Primary sources, shipped fixes, and public writeups or proof-of-concept material where disclosure is complete. Some entries have multiple reporters; this page does not claim sole discovery.
| Date | Target | Finding | Status | Proof |
|---|---|---|---|---|
| trigger.dev | Cross-tenant task replay via missing authorization on replay endpoints | Named reporter · High · fixed in v4.5.2 | GHSA-9fq3-68cw-r7p2 · published advisory names Tom Ryan among the reportersPR #4199 · shipped fix | |
| Vaultwarden | SSO existing-user binding bypassed IdP email verification | Reporter credit · independent duplicate · High · CVE-2026-47164 · fixed in 1.36.0 | GHSA-6x5c-84vm-5j56 · advisory and reporter creditWriteup Public research notes | |
| Linux kernel | CVE-2026-43442: io_uring SQE_MIXED physical-index out-of-bounds read | Patch authored · fixed upstream · backported in 6.19.9 | CVE-2026-43442 · official CVE record6f02c6b19603 · authored by Tom Ryan, merged by Jens Axboe6.19-stable 1f794f9bed3e · stable backport, Greg Kroah-Hartmanliburing a35e4943 · regression testWriteup Public PoC |
Upstream bug fix
Security-relevant engineering work kept separate from the vulnerability count because the upstream team classified it as a bug.
| Date | Target | Finding | Status | Proof |
|---|---|---|---|---|
| V8 / Chrome | Maglev SaveCallSpeculationScope uninitialized read | P2/S2 Bug · fixed upstream · not classified as a vulnerability | Issue 489577364 · public Chromium issueCL 7651434 / 2d111040 · merged fixWriteup Public research notes |
Resolved private report
Anthropic via HackerOne: one resolved report and a $100 bounty. The report's technical details are not public, so the title, affected surface, and reproduction steps are intentionally omitted. Public profile →
Additional reports remain under coordinated disclosure. They will be named here only after the vendor publishes the advisory or fix.
Programs & submissions
- Apple
- Security reports submitted across WebKit and XNU. Unpublished technical details are omitted.
- U.S. DoD VDP
- Authentication reports submitted through HackerOne. Unpublished technical details are omitted.
How I work
The edge is targeting and proof, not volume. I aim AI-driven fuzzers and test harnesses at the specific surfaces that look wrong, then reproduce every promising hit in the target's own compiled code before it leaves my desk. As automated scanners flood maintainers with plausible-but-wrong reports, the bar that matters is a real, reproducible PoC. A screenshot is not proof. That verification step is the work.
Reporting & contact
For coordinated disclosure, email overboardapps@gmail.com, open a private security advisory on the affected repository, or reach me through HackerOne, Bugcrowd, or GitHub. I follow coordinated disclosure and publish writeups only after a fix ships and any embargo lifts. A security.txt is published at the canonical location.
For sensitive reports, encrypt to my PGP key
(Ed25519, fingerprint
2ED8 B42D B037 A499 0967 7B3E C8A3 D6B6 D952 A47C).