Tom Ryan / A5omic

Security

I'm Tom Ryan (A5omic), an independent security researcher. I find and report memory-safety and authorization flaws in widely used software. This page covers findings I reported or contributed to and separates confirmed public vulnerabilities from upstream bugs that were fixed but not classified as security vulnerabilities. Every named finding links to public proof. Reports still under coordinated disclosure stay generalized until the vendor publishes them.

Public record: three publicly documented security findings, one upstream bug fix, and one resolved report whose technical details remain private.

View @a5omic →

Public vulnerabilities

Primary sources, shipped fixes, and public writeups or proof-of-concept material where disclosure is complete. Some entries have multiple reporters; this page does not claim sole discovery.

DateTargetFindingStatusProof
trigger.dev Cross-tenant task replay via missing authorization on replay endpoints Named reporter · High · fixed in v4.5.2 GHSA-9fq3-68cw-r7p2 · published advisory names Tom Ryan among the reporters
PR #4199 · shipped fix
Vaultwarden SSO existing-user binding bypassed IdP email verification Reporter credit · independent duplicate · High · CVE-2026-47164 · fixed in 1.36.0 GHSA-6x5c-84vm-5j56 · advisory and reporter credit
Writeup
Public research notes
Linux kernel CVE-2026-43442: io_uring SQE_MIXED physical-index out-of-bounds read Patch authored · fixed upstream · backported in 6.19.9 CVE-2026-43442 · official CVE record
6f02c6b19603 · authored by Tom Ryan, merged by Jens Axboe
6.19-stable 1f794f9bed3e · stable backport, Greg Kroah-Hartman
liburing a35e4943 · regression test
Writeup
Public PoC

Upstream bug fix

Security-relevant engineering work kept separate from the vulnerability count because the upstream team classified it as a bug.

DateTargetFindingStatusProof
V8 / Chrome Maglev SaveCallSpeculationScope uninitialized read P2/S2 Bug · fixed upstream · not classified as a vulnerability Issue 489577364 · public Chromium issue
CL 7651434 / 2d111040 · merged fix
Writeup
Public research notes

Resolved private report

Anthropic via HackerOne: one resolved report and a $100 bounty. The report's technical details are not public, so the title, affected surface, and reproduction steps are intentionally omitted. Public profile →

Additional reports remain under coordinated disclosure. They will be named here only after the vendor publishes the advisory or fix.

Programs & submissions

Apple
Security reports submitted across WebKit and XNU. Unpublished technical details are omitted.
U.S. DoD VDP
Authentication reports submitted through HackerOne. Unpublished technical details are omitted.

How I work

The edge is targeting and proof, not volume. I aim AI-driven fuzzers and test harnesses at the specific surfaces that look wrong, then reproduce every promising hit in the target's own compiled code before it leaves my desk. As automated scanners flood maintainers with plausible-but-wrong reports, the bar that matters is a real, reproducible PoC. A screenshot is not proof. That verification step is the work.

Reporting & contact

For coordinated disclosure, email overboardapps@gmail.com, open a private security advisory on the affected repository, or reach me through HackerOne, Bugcrowd, or GitHub. I follow coordinated disclosure and publish writeups only after a fix ships and any embargo lifts. A security.txt is published at the canonical location.

For sensitive reports, encrypt to my PGP key (Ed25519, fingerprint 2ED8 B42D B037 A499 0967 7B3E C8A3 D6B6 D952 A47C).