Building Trust in
Critical Systems

We combine applied mathematics, formal methods, and security research to uncover vulnerabilities, verify critical properties, and strengthen the systems your business depends on.

Applied Mathematics • Formal Methods • Computational Engineering
MATHEMATICAL MODELING
Transforming complex scientific and engineering problems into rigorous mathematical representations.
FORMAL METHODS
Developing rigorous methods for specification, verification, reasoning, and provable system properties.
COMPUTATIONAL ENGINEERING
Developing algorithms, software, simulations, and computational methods from mathematical research.

Trusted by

  • Æthux Atlas (USA)
  • Phantom Layer (USA)
  • A K Enterprises (India)
  • Blaze (Brazil)
  • FOGGO (Brazil)
  • Jonbet (Brazil)
  • Godwin Schembri (Switzerland)
  • Federal Police (Brazil)
  • Ministério Público (Brazil)
  • Banco Nacional de Chile (Chile)
About FikreSekhel

Who We Are

FikreSekhel is a research-driven technology company applying mathematics, formal methods, and computational science to complex problems in cybersecurity and bioinformatics.

From mathematical foundations to real-world technology

We believe complex scientific and engineering problems should first be understood through rigorous mathematical models. Our research combines applied mathematics, computer science, formal reasoning, statistical methods, and artificial intelligence.

We transform this research into computational methods, software, technical intelligence, and technologies designed to produce measurable impact in high-complexity environments.

Learn more about FikreSekhel
Mathematical research and computational modeling Scientific research applied to technology
Research

Selected Research & Applied Intelligence

Selected research demonstrating how applied mathematics, formal methods, computational analysis, and scientific experimentation are used to understand complex systems and transform technical findings into operational intelligence.

03
Selected Research Cases
Representative studies currently highlighted across our applied research work.
01
Public Research Credit
Publicly attributable research, coordinated disclosure, and technical recognition.
05+
Systems & Models Analyzed
Software libraries, computational flows, trust boundaries, and mathematical system models.
04
Active Research Tracks
Applied mathematics, formal methods, cybersecurity, and computational biology.
ID Research Case Severity Type Status Disclosure
FR-2026-001
Non-canonical JWT acceptance leading to revocation and rate-limit bypass
A trust mismatch between verification and application-layer token handling can allow variant tokens to remain valid while revocation and policy checks rely on strict string comparison.
High Authentication / Logic Flaw Coordinated Disclosure Report available on request
FR-2026-002
RPC response spoofing via postMessage trust boundary violation
Browser messaging trust assumptions can break when response handling is not strongly bound to source, origin, and expected request lifecycle.
High Client-side Trust Boundary Publicly Discussed Disclosure summary available
FR-2026-003
AES-CBC malleability enabling privilege bit-flipping in application workflows
Encryption schemes without integrity guarantees can permit controlled ciphertext manipulation, resulting in altered protected values and unsafe application decisions.
Critical Cryptographic Design Flaw Research Complete Private / pending publication

Research Method

Each research problem is translated into a formal or computational model, investigated through reproducible experiments, and evaluated against its scientific, technical, and operational consequences.

  • • Problem definition and mathematical abstraction
  • • Formal reasoning, computational modeling, and hypothesis development
  • • Reproducible experiments and empirical validation
  • • Structural, statistical, and operational analysis
  • • Translation of findings into technology and measurable impact

From Research to Applied Intelligence

Our work combines mathematical modeling, formal methods, static and dynamic analysis, statistical reasoning, and computational experimentation. The methodology is adapted to each research domain, from software security and cryptographic systems to genomic data and biological computation.

Research outcomes are transformed into reproducible methods, technical reports, computational tools, software, and operational intelligence. This allows complex scientific findings to become practical technologies capable of supporting real-world decisions.

Security Research

Vulnerability Discoveries & Advisories

Selected vulnerability discoveries, security reports, and public acknowledgements from FikreSekhel and its founder, including earlier independent research published under the name Franciny Salles.

Library / Product Finding Severity CVE Public Advisory / Reference
@hiprax/crypto
Cryptographic library
Pre-authentication resource amplification via unauthenticated KDF parameters
Attacker-controlled key derivation parameters in the ciphertext header can cause excessive resource consumption before ciphertext authentication, creating a denial-of-service risk.
Moderate Pending assignment GHSA-fgpf-v2mm-vhx6
fast-jwt
JSON Web Token library
Cache key collisions causing identity and authorization confusion
When caching is enabled with a collision-prone custom cacheKeyBuilder, verification can return claims from a different token, potentially causing impersonation or privilege escalation. Default caching is unaffected.
Critical CVE-2026-35039 GHSA-rp9m-7r4c-75qg
Reporter: Franciny Rojas (@fasrm)
fast-jwt
JSON Web Token library
Stateful regular expressions causing inconsistent claim validation
Reusing regular expressions with /g or /y flags in allowed-claim checks can cause the same valid token to alternate between acceptance and rejection. This can disrupt authentication and trigger retries. The issue does not allow invalid tokens to be accepted.
Patched version: 6.2.1.
Moderate CVE-2026-35040 GHSA-3j8v-cgw4-2g6q
Reporter: Franciny Rojas (@fasrm)
protobuf.js
Protocol Buffers library
Denial of service through unbounded JSON descriptor recursion
Deeply nested, untrusted JSON descriptors processed by Root.fromJSON() or Namespace.addJSON() can exhaust the JavaScript call stack, causing descriptor loading to fail or potentially crashing the process.
Moderate CVE-2026-45740 GHSA-jggg-4jg4-v7c6
Reporter: Franciny Rojas (@fasrm)
multer
Multipart upload middleware
Denial of service through incomplete cleanup of aborted uploads
Aborted or malformed multipart uploads can leave orphaned partial files when diskStorage is used. Repeated requests can accumulate these files, exhaust disk space, and cause denial of service.
Moderate CVE-2026-5038 GHSA-3p4h-7m6x-2hcm
Credited finder: Franciny Rojas (@fasrm)
ssh2
SSH client and server library for Node.js
Out-of-bounds write in the Windows Pageant helper
The report identified an unchecked copy in the native Pageant helper, where an input length could exceed a fixed-size shared-memory region. The maintainer responded by removing Pageant support.
Resolution: affected functionality removed upstream.
Not rated Not confirmed Issue #1498
Reporter: Franciny Rojas (@fasrm)
Axios
HTTP client for JavaScript
Custom credential headers forwarded across cross-origin redirects
The report demonstrates that custom secret-bearing headers can be forwarded to a different origin during redirects, even when the standard Authorization header is removed. It proposes configurable handling of sensitive headers.
Public hardening report; maintainer validation has not been confirmed.
Not rated Not confirmed Issue #10711
Reporter: Franciny Rojas (@fasrm)
Ponytail
Python benchmark component
Unrestricted URI scheme handling in benchmark-local.py
The --ollama-url argument reaches urllib.request.urlopen() without scheme validation, allowing schemes such as file:// and FTP. The maintainer acknowledged the report and agreed that an HTTP/HTTPS allowlist was appropriate.
No practical remote code execution or data exfiltration was demonstrated. The public issue is closed.
Not rated Not confirmed Issue #166
Reporter: Franciny Rojas (@fasrm)
WampServer
Web development environment
Cross-site scripting in index.php
A cross-site scripting vulnerability in the index.php localhost page, credited to Franciny Salles in the vendor changelog. The fix is documented in the WampServer 3.1.5 release notes.
Medium
NVD CVSS 3.0: 6.1
CVE-2018-1000848 Vendor changelog
Credited researcher: Franciny Salles

Severity labels follow the referenced GitHub advisories or the identified NVD assessment. "Not rated" indicates that no formal severity rating is documented here. "Not confirmed" indicates that a CVE identifier has not been verified for that entry. Public reports are distinguished from confirmed advisories in their descriptions.

Bring Us Your Most Complex Problem

Work with FikreSekhel to transform complex scientific and engineering problems into mathematical models, computational methods, and practical technologies.