Sebastián Alba Vives, Security Research

Sebastián Alba Vives

Independent security researcher · San José, Costa Rica

I like soccer, I collect Toy Story figures, I make digital art, and I eat a lot of cereal. I also work as a Cybersecurity Manager. And I like hacking things until they break, which is how most of the list below happened.

GitHub LinkedIn

Organizations

Organizations where I reported vulnerabilities or contributed fixes

Record
00
CVE assignments63
Vulnerabilities reported80+
Organizations37+
Public acknowledgements13
Awarded patents1
Public acknowledgements (13)
  • Microsoft MSRC Special Mention

    Acknowledged for valid vulnerability reports submitted during the 2025-26 recognition period, including a command injection in Microsoft Muzic and memory-safety findings in ONNX Runtime Extensions.

    Open MSRC page View mention

  • Harvard University Letter of Appreciation

    Eight reports to the Vulnerability Disclosure Program, three critical, including a confirmed RCE on FAS Research Computing. Five remediated.

    Open letter (PDF)

  • CERN Computer Security Kudos

    Listed on the Computer Security Team’s public Kudos page for findings in ROOT and Geant4, the frameworks behind Large Hadron Collider data analysis.

    Open Kudos page

  • U.S. Department of Defense VDP recognition

    Report triaged and resolved by the DoD security team through the Defense Cyber Crime Center programme on HackerOne.

    View resolution

  • Palo Alto Networks Researcher Acknowledgement

    XML injection in the pan-os-python SDK. Confirmed by PSIRT, fixed, rewarded through the bug bounty programme, and credited on the public acknowledgement page.

    Open acknowledgement View fix

  • GOVCERT.LU Hall of Fame · Luxembourg

    Four vulnerabilities in eml_parser, the email parsing library the Government of Luxembourg’s CERT maintains for SOC pipelines. All patched in v3.0.2.

    Open Hall of Fame

  • Universiteit Utrecht Hall of Fame · Netherlands

    Listed for responsible disclosure of security vulnerabilities reported to the university’s IT services team.

    Open Hall of Fame

  • PAX Technology Letter of Appreciation

    Four findings in the PAXSTORE SDKs used by point-of-sale terminals. Fixed in v11.0.1 and v10.2.1, with a formal letter and a hand-carved sandalwood fan inscribed “PAX Security Contributor”.

    Open letter (PDF) Release notes

  • National Instruments Security advisory credit

    Credited by name in the official advisory for seven vulnerabilities in the gRPC Device Server, two of them critical. All patched in v2.18.0.

    Open advisory

  • Bitdefender Bug Bounty Hall of Fame

    Two out-of-bounds writes in Napoca, their bare-metal hypervisor, both reachable from a guest virtual machine.

    Open Hall of Fame

  • Kaspersky PSIRT acknowledgements

    Memory-safety issues in the Neuromorphic Platform, their framework for running spiking neural networks on specialised inference hardware.

    Open acknowledgements

  • OWASP Two Letters of Recognition

    A stored XSS and a server-side template injection in OWASP Cervantes. Both acknowledged with individual letters signed by the project leader.

    Letter, XSS (PDF) Letter, SSTI (PDF)

  • DSCI Letter of Appreciation · India

    Three vulnerabilities in the national Threat Intelligence Platform, including unauthenticated access to configuration data. Letter issued by the CEO.

    Open letter (PDF)

Assigned CVEs (63)
TargetClassCVEs
OOB write · type confusion17
National Instruments gRPC Device Server

CVE-2026-48137 · CVE-2026-48138 · CVE-2026-48139 · CVE-2026-48140 · CVE-2026-48141 · CVE-2026-9142 · CVE-2026-9143

untrusted pointer deref7
OOB read · truncation7
GOVCERT.LU eml_parser · Government of Luxembourg

CVE-2026-44844 · CVE-2026-55618 · CVE-2026-55619 · CVE-2026-55620

quadratic DoS · recursion4
Rapid7 InsightConnect sed plugin

CVE-2026-9153 · CVE-2026-9154 · CVE-2026-9155

command injection3
reachable assertion2
CorosyncRed Hat Enterprise Linux HA

CVE-2026-35091 · CVE-2026-35092

integer underflow2
389 Directory ServerRed Hat Directory Server, FreeIPA

CVE-2026-15722

stack buffer overflow1
BitdefenderNapoca hypervisor

CVE-2026-10046 · CVE-2026-10047

guest-to-host OOB write2
heap overflow2
GNOMElibsoup WebSocket parser

CVE-2026-15711

unbounded allocation1
MIT Kerberos 5

CVE-2026-11850

integer underflow1
IBMopenCryptoki PKCS#11

CVE-2026-40253

heap OOB write1
Eclipse OpenJ9JITServer

CVE-2026-6918

pre-auth OOB read1
ValveSteam Audio SDK

CVE-2026-38796

missing verifier1
SuricataDNP3 decoder

CVE-2026-45765

OOB write1
Crypto++BLAKE2

CVE-2026-38800

assert-only bounds1
heap OOB write1
VM OOB read1
ArmArmNN TFLite parser

CVE-2026-42627

integer overflow1
SDL_imageXCF decoder

CVE-2026-35444

heap OOB read1
OOB read1
Open WebUI

CVE-2026-45338

SSRF1
BytebaseDBHub

CVE-2026-38795

SQL injection bypass1
Kyndrylhashi-vault-js

CVE-2026-55100

path traversal1
KNMIadaguc-server

CVE-2026-50126

OOB read1
Confirmed and fixed, no CVE (17)

Reports the vendor accepted and patched where no identifier was issued either the project is not a CNA, or it was handled as a hardening fix.

  • RCE · CVSS 9.8 · LoA Harvard University Vulnerability Disclosure Program

    Unauthenticated Ray Dashboard on FAS Research Computing, an open eXist-db REST API serving 624 documents, and a switch management interface reachable from the internet with no password. Eight reports, five remediated.

    Open letter (PDF)

  • CWE-91 · bounty paid Palo Alto Networks pan-os-python SDK

    XML injection in the HA configuration sync path: unescaped user values let an attacker smuggle sibling elements into the request sent to the firewall. Fixed in PR #614.

    View fix (PR #614)

  • CWE-125 · fix merged Cisco Talos ClamAV

    The HFS+ attribute parser validated a name length as a UTF-16 character count, then used the same field as a byte offset. Fix merged with credit in PR #1708.

    View fix (PR #1708)

  • 4 findings · LoA PAX Technology PAXSTORE SDKs

    Zip Slip during terminal parameter extraction, XXE chained onto it, a shared key hardcoded in the public repository behind ten PBKDF2 iterations, and a TrustManager that accepted every certificate.

    Open letter (PDF)Release notes

  • Kudos page CERN ROOT, Geant4 & Delphes

    Memory-safety issues in the data-analysis framework used across high-energy physics, plus the first CVE ever assigned in Geant4's history.

    Open Kudos page

  • pre-auth OOB write hostapd EHT/MLO, Wi-Fi 7

    Out-of-bounds write reachable before authentication in the multi-link element handling.

    Aviso de seguridad

  • PSIRT bulletin Kaspersky Neuromorphic Platform

    Memory-safety issues in the FlatBuffers and ZMQ communication layer of their spiking neural network framework.

    Open acknowledgements

  • triaged · resolved U.S. Department of Defense DC3 VDP

    Report accepted and resolved through the Defense Cyber Crime Center programme on HackerOne.

    View resolution

  • first CVE in the project CERN Geant4 & Delphes

    Geant4 simulates how particles travel through matter. It is used at the Large Hadron Collider, in NASA and ESA mission planning, and to plan radiotherapy doses in hospitals. The finding became the first CVE ever assigned in the project's history.

    Open Kudos page

  • backported to 5 stable trees Linux Kernel drivers/fpga

    Memory-safety fixes in the FPGA manager subsystem, accepted upstream and backported by the stable maintainers to five kernel branches.

    lore.kernel.org

  • reported upstream Raspberry Pi Linux kernel fork

    Driver issue in the kernel tree that ships on the single-board computers used across education, hobby projects and industrial deployments.

    PR #7327

  • Valve · Proton vkd3d-proton DirectX 12 to Vulkan

    Overflow in graphics resource allocation. This is the translation layer that lets Windows games run on Linux and on the Steam Deck.

    PR #2926

  • CWE-787 Ghostscript XPS parser

    Memory-safety issue in the document parser. Ghostscript is the PostScript and PDF engine behind most printing on Linux and in print servers.

    Bug #709292

  • boot path U-Boot NFS boot

    Issue in the network boot path of the bootloader that starts most embedded Linux devices, from home routers to industrial equipment.

    Patches

  • RISC-V target QEMU RISC-V emulation

    Issue in the RISC-V target of the emulator that underpins most Linux virtualisation, including cloud infrastructure.

    Commit b2e874b

  • 3 findings · LoA DSCI national Threat Intelligence Platform

    India's national cybersecurity council, founded by NASSCOM. Three vulnerabilities in the platform used to monitor threats against national infrastructure, including unauthenticated access to configuration data and source code exposure. All patched.

    Open letter (PDF)

  • 2 findings · 2 LoR OWASP Cervantes

    A stored cross-site scripting flaw and a server-side template injection in the vulnerability management project. Both acknowledged with individual Letters of Recognition signed by the project leader.

    Letter, XSS (PDF) Letter, SSTI (PDF)

Where the bugs live
MS-DOS Prompt
C:\> vuln-audit --breakdown --all [scan] 68 findings across 63 CVEs / 26 targets SOURCE LANGUAGE -------------------------------------------------- C ████████████████████████████ 38 55.9% C++ ████████████████ 22 32.4% Python ███ 4 5.9% Assembly 2 2.9% Shell/Make 2 2.9% BUG CLASS -------------------------------------------------- OOB Read 125 ██████████████████████████████ 16 reading past the buffer OOB Write 787 ██████████████████ 10 writing past the buffer Int Over/Under190 █████████████████ 9 arithmetic that wraps Heap Overflow 122 █████████████ 7 overflowing a heap buffer Stack Overflow121 █████ 3 overflowing the call stack Auth/Pointer 822 █████ 3 unchecked pointers or auth TOOLCHAIN -------------------------------------------------- Manual review ████████████████████████████ 40x reading code line by line grep/ripgrep ██████████████████████████ 38x searching for dangerous patterns ASAN/UBSAN ███████████████ 22x confirming the crash gdb/pwndbg/rr ████████████ 18x finding the root cause AFL++/libFuzzer █████████ 14x testing random inputs Ghidra/radare2 ███ 5x analysing without source [done] 63 CVEs · 26 targets · 68 findings (all of this worked on my machine) ¯\_(ツ)_/¯ C:\>_
Patent
i
Cinta Conductora de Electricidad
Electrical Conductive Tape, utility model, Costa Rica
PublicationCR20160103 (U)
ApplicationCR20160103U
Filed2016-03-02
Published2016-04-27
IPC classH01B7/08

Innovation Champion 2015, MICITT. Intel ISEF finalist.

View on Espacenet

Press and other work
  • La Republica · Costa Rica Students create a tape that promises to end short-circuit fires

    National coverage of the patented conductive tape, back when it was still a student project.

    Read article

  • La Republica · Costa Rica Top 5 in the World Photographic Cup

    Costa Rica's national team placed in the top five worldwide in the Commercial and Illustration categories.

    Read article

  • TEC · Costa Rica Institute of Technology "My passion is engineering, but photography is inside me"

    Interview about balancing engineering and photography.

    Read interview

  • JPGBOOK · 2020 edition Featured artist

    Photographic work selected for the 2020 edition.

It’s now safe to turn off your computer.
Ready 63 CVEs 37 organizations 1 patent
Sebastián Alba Vives, Security Research --:--