Partial Message State Retention After Failed Protobuf Parsing
Why Parse Failure Does Not Necessarily Mean Object Sanitization in Protocol Buffers
Featured
Experimental analysis of Protocol Buffers C++ demonstrating that malformed protobuf payloads may leave partially decoded application state available even after ParseFromString() returns false.
CategoryParser Security
EcosystemProtocol Buffers
DifficultyAdvanced
FikreSekhel Research15 min readJun 02, 2026
Research Notes
Credential Boundary Drift Across Cross-Origin Redirects
How partial redirect protections can preserve custom authentication headers across origin changes
Featured
A research note examining custom credential-bearing headers, redirect trust boundaries, and partial stripping behavior in HTTP clients.
CategoryHTTP Client Security
EcosystemJavaScript / HTTP Clients
DifficultyAdvanced
FikreSekhel Research14 min readJun 01, 2026
Research Notes
Promise Resolution as a Sandbox Boundary
A vm2 case study in asynchronous host-to-sandbox boundary mediation failure
Featured
A research note examining Promise resolution as a security-sensitive cross-realm boundary in JavaScript sandbox architectures.
CategorySandbox Isolation Security
EcosystemJavaScript / VM Isolation
DifficultyResearch
FikreSekhel Research18 min readJun 01, 2026
Research Notes
Recursive Descriptor Expansion as an Availability Primitive
How unbounded structural recursion transforms schema loading into denial-of-service surface
Featured
A research note examining recursion depth exhaustion in descriptor expansion pipelines.