Skip to content
View AL-Cybision's full-sized avatar
  • Gray

Block or report AL-Cybision

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AL-Cybision/README.md

👨🏻‍💼 Muhammad Noman Ilyas (AL-Cybision)

🛡️ Application Security & Vulnerability Researcher
🔗 Huntr Profile : https://huntr.com/users/al-cybision 🔗 HackerOne Profile : https://hackerone.com/al_cybision

GitHub FollowersLinkedIn


OSWE Badge

🔍 SECURE CODE REVIEW🛡️ VULNERABILITY RESEARCH🤖 AI/ML MODEL FILE VULNS


Highlights

🪲 Vulnerabilities Discovered

CVE IDCVSSProjectSummaryReferences
CVE-2026-6691🔴 8.6 High🍃 MongoDB C DriverCyrus SASL username canonicalization heap buffer overflow via unsafe string copy leads to RCE & DoSCDRIVER-6134
CVE-2025-11157🔴 7.8 High🍽️ FeastUnsafe PyYAML deserialization in Kubernetes materializer enables arbitrary code executionFix PR #5643 / Huntr Report
CVE-2025-59420🔴 7.5 High🔐 AuthlibJWT/JWS accepts unknown crit headers → possible authz bypassGHSA-9ggr-2464-2j32
CVE-2025-61920🔴 7.5 High🔐 AuthlibDoS via oversized JOSE segmentsGHSA-pq5p-34cr-23v9
CVE-2025-62706🟡 6.5 Medium🔐 Authlibzip=DEF decompression bomb enables DoSGHSA-g7f3-828f-7h7m

🔒 Private Validated Findings

StatusAreaPublic-safe summary
Private / Validatedjoblib model-file securityLoad-time model artifact deserialization issue leading to code-execution risk and scanner-evasion behavior. Technical details withheld until disclosure.
Private / ValidatedKeras .keras model-file securitySafe-mode model-loading bypass class involving model configuration/data-loading behavior, aligned with later public Keras CVE-2025-12058 research. Technical details withheld until disclosure.

🤝 Contributions

ProjectDescriptionVersionLink
Go-JoseFixed bug: b64 header ignored in unprotected header (now rejected).v4.1.3PR #210
AuthlibCollaborated on patch for critical header validation bypass.v1.6.4PR #823

Pinned Loading

  1. authlib/authlibauthlib/authlibPublic

    The ultimate Python library in building OAuth, OpenID Connect clients and servers. JWS, JWE, JWK, JWA, JWT included.

    Python 5.4k 556

  2. go-josego-josePublic

    Forked from go-jose/go-jose

    An implementation of JOSE standards (JWE, JWS, JWT) in Go

    Go

  3. huggingface/huggingface_hubhuggingface/huggingface_hubPublic

    The official CLI and Python client for the Hugging Face Hub.

    Python 3.8k 1.2k