About

I'm Kaya Emre Arıkan — an independent security researcher. I spend most of my time reading source code, tracing patch diffs, and looking for the class of bugs that survive a code review because nobody thought to check the boundary condition: auth bypasses, injection, deserialization, race conditions, and the odd firmware-level RCE.

My research spans open-source ecosystems — web frameworks, cloud SDKs, container runtimes, CI tooling, and the occasional piece of embedded firmware — reported through coordinated disclosure to maintainers, CNAs, and bug bounty programs (HackerOne, Bugcrowd, GitHub Security Advisories, MSRC, Google OSS VRP).

What's on this site

Writeups of my own findings — published only after the vendor's own advisory (CVE / GHSA / security bulletin) is already public. Nothing here pre-empts a disclosure still in progress.

Elsewhere

github.com/kemrec

Disclosure policy: every vulnerability is reported privately to the affected vendor or maintainer first. I follow coordinated disclosure and only publish technical details once a public advisory already exists — never before, regardless of vendor response time.