Skip to content
TideCore TECHNOLOGY Request an Appointment
Security Research & Open Source

Security research grounded in real systems.

TideCore founder Charles Vosburgh conducts independent vulnerability research across open-source software and contributes security and correctness work upstream to the Linux kernel.

The work emphasizes reproducible evidence, responsible disclosure, real-world impact, remediation validation, and clear technical documentation.

21
Public Vulnerability Cases

Distinct publicly disclosed findings.

14
Public CVEs

Named in a public advisory or CVE record.

12
Published Repository GHSAs

Maintainer-published repository advisories.

4
Accepted Linux Mainline Security Fixes

Public author or reporter credit upstream.

2 Authored kernel fixes — written and signed off upstream
2 Reported-by kernel fixes — patches authored by the maintainer
6 Verified stable-tree backports of the first authored SCTP fix

Counting note. Some findings carry both a CVE and a repository GHSA, so identifier totals overlap. The defensible unique total is 21 distinct public vulnerability cases — the identifier counts are not added together. Figures verified against public sources on 2026-09-05.

Featured Research

Selected public vulnerability cases.

Each case below links to the independent public advisory record. Credit roles are reproduced exactly as the coordinator published them.

Java / JVM Apache: Important · CISA ADP: 9.8 Critical

Apache Fory

CVE-2026-64606

Class-registration bypass through an auto-admitted SerializedLambda capture interface

Credit
Charles Vosburgh — reporter
Weakness
CWE-502
Fixed in
1.4.0
npm 7.8 High

TypeBox

CVE-2026-77356 · GHSA-976x-prgx-qv35

Schema-controlled values could escape generated validation code

Credit
Finder — also credited for reporting and fix verification
Weakness
CWE-94
Fixed in
Patched across maintained 0.x lines
npm 8.8 High

isomorphic-git

CVE-2026-77355 · GHSA-6fxm-h49m-4fg3

Windows NTFS `.git::$INDEX_ALLOCATION` alias bypass could write into the active gitdir

Credit
Reporter
Weakness
CWE-22
Fixed in
1.38.7
npm 9.8 Critical

vm2

CVE-2026-47698 · GHSA-cfcw-xp6x-25gj

Sandbox breakout through stacked indirection around dangerous host prototype mutators

Credit
Co-reporter — shared credit on the public advisory
Weakness
CWE-913
Fixed in
3.11.6
npm 8.7 High

fast-xml-parser

CVE-2026-73569 · GHSA-8r6m-32jq-jx6q

Repeated DOCTYPE declarations reset entity-expansion limits, enabling resource exhaustion

Credit
Reporter
Weakness
CWE-776
Fixed in
5.10.1
C / C++ 6.5 Moderate

libheif

CVE-2026-84451 · GHSA-hh47-fhqr-cj2r

Incomplete fix left a sibling range check vulnerable to integer wrap and an out-of-bounds read

Credit
Co-reporter — advisory credits three reporters
Weakness
CWE-125
Fixed in
1.23.3

The full public record — every identifier, every advisory link — is maintained on SecHive.ai ↗.

Linux Kernel

Four accepted mainline security fixes.

Kernel credit is recorded exactly as the mainline commits state it. Two fixes were authored and signed off by Charles; two KSMBD fixes carry Reported-by: Charles Vosburgh with patches authored by Namjae Jeon. Reporting a bug and authoring the accepted patch are different contributions and are not merged into one claim.

net/sctp Patch author

sctp: validate Adaptation Indication parameter length

A header-only Adaptation Layer Indication parameter passed generic validation, after which the kernel read a 32-bit value beyond the declared parameter and could return receive-buffer tail bytes to the peer in the state cookie.

Six verified stable-tree backports
74b21f52c5c5 ↗
net/sctp Patch author

sctp: validate chunk length in the inqueue parser

The inqueue parser accepted chunks whose declared length was shorter than the four-byte chunk header. The fix rejects them at the parser boundary before further processing.

Acked-by Xin Long · applied by Jakub Kicinski
6cfc1b90cb86 ↗
fs/smb/server Reported-by

ksmbd: preserve VFS inherited POSIX ACL mask

Prevents SMB object creation from widening effective permissions after VFS ACL inheritance.

Selected for AUTOSEL 6.18–6.6 — queued, not yet backported
e148e567a925 ↗
fs/smb/server Reported-by

ksmbd: enforce signing required by the session

Rejects unsigned plaintext requests when the SMB session requires signing.

Reviewed and tested by ChenXiaoSong · signed into the SMB tree
2bebf2470af1 ↗

Also public, not counted. A cert-manager remediation pull request publicly credits the reporter and is Open and ready for review — not merged and not maintainer-approved. It is deliberately excluded from the accepted-fix total above. View the PR ↗

Research Tooling

Building the tools behind the research.

SecHive.ai is an operator-driven security research workbench: the operator sets scope and authorization, and every hypothesis is validated, evidenced, and reviewed by a human before anything is disclosed.

  1. 01Scope
  2. 02Hypothesis
  3. 03Validation
  4. 04Evidence
  5. 05Human review
  6. 06Disclosure

SecHive supports this research; it is not presented as the origin of every finding above. Where an advisory credits multiple reporters, that shared attribution is preserved.

Explore SecHive.ai ↗
Responsible Disclosure

Published only when disclosure permits.

Research is coordinated privately with maintainers and vendors. Public technical material is released only when disclosure status permits, with emphasis on reproducible evidence, remediation validation, and regression prevention.

Additional CVE assignments and reservations remain under coordinated disclosure. Their identifiers and affected products stay private until the responsible coordinator publishes. Where a coordinator has published an advisory but is still withholding a proof of concept, only the public summary appears here.

Need practical help with your technology?

TideCore's day-to-day work is home and small-business technology support — Wi-Fi, computers, networking, and small-office systems.