About Pavan Nallamothu

Pavan Nallamothu is an independent security researcher known for 12 published CVEs credited by Apple, CISA, and the NSA, and for coining EPI-SSRF (Egress-Path-Incomplete SSRF).

Security Researcher Penetration Tester Jersey City, New Jersey M.S. Cybersecurity, Pace University

At a glance

NamePavan Nallamothu
RoleIndependent security researcher and penetration tester
LocationJersey City, New Jersey, United States
EducationM.S. Cybersecurity, Pace University, 2023 to 2025 (Graduate Merit Scholarship)
FieldVulnerability research, coordinated disclosure, web and cloud application security, offensive security tooling
Published CVEs12, credited by Apple, CISA (Malcolm), the NSA (skills-service), AutoGPT, yt-dlp, and blueprintUE. Index: CVE advisories
Coined termEPI-SSRF (Egress-Path-Incomplete SSRF), defined in SSRF Beyond HTTP. Wikidata concept Q141378276
PapersTwo open-access papers with DOIs, listed under Publications and indexed on ORCID
Open source62 projects, including 60 systems tools written from scratch in Rust, each with its own repository and live page. Index: Open-Source Builds
ReceiptsEvery contribution mapped to its independent source on the verification table

The short version

What the work is, and what it is not.

I find vulnerabilities in software that people already run, report them through coordinated disclosure, and publish the reproduction. The published record is 12 CVEs, credited by Apple, CISA, the NSA, AutoGPT, yt-dlp, and blueprintUE. Each one has a page on this site that links the authoritative advisory, so the credit can be checked at the source rather than taken on my word.

My research sits in one lane: server-side request forgery and the guards meant to stop it. That work produced EPI-SSRF, a named class where an egress guard covers only some of the outbound clients, so an alternate path such as SMTP walks past it. The paper that defines it is open access, and the term has a Wikidata concept item so machines can resolve it as a real thing rather than a phrase I repeat.

The rest of my time goes into building the software I break. Sixty systems tools written from scratch in Rust, from compilers and kernels to databases, browser engines, and security tooling, plus two standalone projects. Building a thing from the lowest level up is how I learn where its assumptions fail, and every tool here is open source under MIT.

This page is the canonical profile. The Experience and Education sections on the homepage carry the full record, and the researcher profile carries the receipts.

Where each claim is verifiable

No claim on this site is meant to be believed. Each one resolves to a page someone else controls.

ClaimIndependent source
Apple credited the reporter on CVE-2026-43763support.apple.com
CISA Malcolm inode-exhaustion DoS, CVE-2026-63133GHSA-c35g-mgc3-95rx
CISA Malcolm archive path traversal, CVE-2026-63134GHSA-65mm-vgrw-vqx4
CISA Malcolm RBAC bypass, CVE-2026-63177GHSA-m5fr-rv3h-xg2r
NSA skills-service privilege escalation, CVE-2026-63013GHSA-67x3-r85f-822r
NSA skills-service cross-project IDOR, CVE-2026-63014GHSA-p527-vjfp-c43p
AutoGPT SSRF via a user-controlled SMTP server, CVE-2026-33234GHSA-4jwj-6mg5-wrwf
yt-dlp dangerous file creation, CVE-2026-50023GHSA-c6mh-fpjc-4pr3
Four blueprintUE advisories, CVE-2026-40585 to 40588blueprintue advisories
EPI-SSRF defined in a published paperDOI 10.5281/zenodo.22075470
Trusting the Filename paperDOI 10.5281/zenodo.22075439
Researcher identity and worksORCID and Wikidata Q141119059

Same name, different people

Disambiguation, because the name is shared.

More than one person is named Pavan Nallamothu. This site belongs to the security researcher based in Jersey City, New Jersey, whose work is vulnerability research, coordinated disclosure, and the EPI-SSRF research. It is not the work of a semiconductor or chip engineer, and it is not the work of the inventor credited on patent filings in Texas. Those are different people.

Every identifier on this page resolves to this Pavan Nallamothu. ORCID, Wikidata Q141119059, and the verification table are the fastest way to confirm which one you are reading.

Identifiers and profiles

One entity, linked once. Everything here points back to this profile.