Skip to content

Request to volunteer with Node.js security triage #1881

Description

@Nadav0077

Hi, my name is Nadav, and I’m a security researcher interested in contributing to the Node.js security triage team.

I have professional experience working as a security researcher, where I analyze vulnerabilities, reproduce security issues, determine affected versions, evaluate exploitability and impact, investigate false positives and false negatives, and communicate technical findings clearly. In addition to my professional work, I conduct independent vulnerability research and have reported several vulnerabilities that received CVEs across npm, Python and Go packages. My oss research has covered issues such as denial of service, authentication flaws, SSRF, WebSocket vulnerabilities and HTTP parsing problems in major and widely used libraries and packages.

I would be glad to help reproduce and validate reports, identify duplicates, review affected versions, assess severity and impact, communicate with researchers when additional information is needed, and help determine whether reports fall within the Node.js threat model.

I understand that security triage involves access to sensitive and embargoed information, and I am comfortable following the project’s confidentiality, responsible disclosure and security requirements.

Here are some relevant links:

HackerOne
Published advisories
llhttp
My linkedin profile

Thank you for considering my request. I would appreciate any guidance on the best way to begin contributing.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions