// Security Advisories
Vulnerabilities I’ve discovered and disclosed, tracked under the BVE-YYYY-NNNN identifier scheme.
- BVE-2026-0008 Pending
- BVE-2026-0007 STIGQter: Local Code Execution via Crafted .stigqter Project File + Export HTML (User Interaction Required)
- BVE-2026-0006 Pending
- BVE-2026-0005 Pending
- BVE-2026-0004 Pending
- BVE-2026-0003 ok_json: heap buffer overread in true/false/null keyword matching
- BVE-2026-0002 ok_json: heap buffer overread in UTF-8 validation
- BVE-2026-0001 ok_json: heap buffer overread in \uXXXX escape parsing