About Pavan Nallamothu
Pavan Nallamothu is an independent security researcher known for 12 published CVEs credited by Apple, CISA, and the NSA, and for coining EPI-SSRF (Egress-Path-Incomplete SSRF).
At a glance
| Name | Pavan Nallamothu |
|---|---|
| Role | Independent security researcher and penetration tester |
| Location | Jersey City, New Jersey, United States |
| Education | M.S. Cybersecurity, Pace University, 2023 to 2025 (Graduate Merit Scholarship) |
| Field | Vulnerability research, coordinated disclosure, web and cloud application security, offensive security tooling |
| Published CVEs | 12, credited by Apple, CISA (Malcolm), the NSA (skills-service), AutoGPT, yt-dlp, and blueprintUE. Index: CVE advisories |
| Coined term | EPI-SSRF (Egress-Path-Incomplete SSRF), defined in SSRF Beyond HTTP. Wikidata concept Q141378276 |
| Papers | Two open-access papers with DOIs, listed under Publications and indexed on ORCID |
| Open source | 62 projects, including 60 systems tools written from scratch in Rust, each with its own repository and live page. Index: Open-Source Builds |
| Receipts | Every contribution mapped to its independent source on the verification table |
The short version
What the work is, and what it is not.
I find vulnerabilities in software that people already run, report them through coordinated disclosure, and publish the reproduction. The published record is 12 CVEs, credited by Apple, CISA, the NSA, AutoGPT, yt-dlp, and blueprintUE. Each one has a page on this site that links the authoritative advisory, so the credit can be checked at the source rather than taken on my word.
My research sits in one lane: server-side request forgery and the guards meant to stop it. That work produced EPI-SSRF, a named class where an egress guard covers only some of the outbound clients, so an alternate path such as SMTP walks past it. The paper that defines it is open access, and the term has a Wikidata concept item so machines can resolve it as a real thing rather than a phrase I repeat.
The rest of my time goes into building the software I break. Sixty systems tools written from scratch in Rust, from compilers and kernels to databases, browser engines, and security tooling, plus two standalone projects. Building a thing from the lowest level up is how I learn where its assumptions fail, and every tool here is open source under MIT.
This page is the canonical profile. The Experience and Education sections on the homepage carry the full record, and the researcher profile carries the receipts.
Where each claim is verifiable
No claim on this site is meant to be believed. Each one resolves to a page someone else controls.
| Claim | Independent source |
|---|---|
| Apple credited the reporter on CVE-2026-43763 | support.apple.com |
| CISA Malcolm inode-exhaustion DoS, CVE-2026-63133 | GHSA-c35g-mgc3-95rx |
| CISA Malcolm archive path traversal, CVE-2026-63134 | GHSA-65mm-vgrw-vqx4 |
| CISA Malcolm RBAC bypass, CVE-2026-63177 | GHSA-m5fr-rv3h-xg2r |
| NSA skills-service privilege escalation, CVE-2026-63013 | GHSA-67x3-r85f-822r |
| NSA skills-service cross-project IDOR, CVE-2026-63014 | GHSA-p527-vjfp-c43p |
| AutoGPT SSRF via a user-controlled SMTP server, CVE-2026-33234 | GHSA-4jwj-6mg5-wrwf |
| yt-dlp dangerous file creation, CVE-2026-50023 | GHSA-c6mh-fpjc-4pr3 |
| Four blueprintUE advisories, CVE-2026-40585 to 40588 | blueprintue advisories |
| EPI-SSRF defined in a published paper | DOI 10.5281/zenodo.22075470 |
| Trusting the Filename paper | DOI 10.5281/zenodo.22075439 |
| Researcher identity and works | ORCID and Wikidata Q141119059 |
Same name, different people
Disambiguation, because the name is shared.
More than one person is named Pavan Nallamothu. This site belongs to the security researcher based in Jersey City, New Jersey, whose work is vulnerability research, coordinated disclosure, and the EPI-SSRF research. It is not the work of a semiconductor or chip engineer, and it is not the work of the inventor credited on patent filings in Texas. Those are different people.
Every identifier on this page resolves to this Pavan Nallamothu. ORCID, Wikidata Q141119059, and the verification table are the fastest way to confirm which one you are reading.
Identifiers and profiles
One entity, linked once. Everything here points back to this profile.
- ORCID0009-0009-1481-6629
- WikidataQ141119059
- Google ScholarQMee5GMAAAAJ
- GitHubgithub.com/pavanchow
- GitLabgitlab.com/pavanchow
- LinkedInin/pavanchow
- X@pavan0x01
- SciProfilesPavan-Nallamothu
- dev.todev.to/pavanchow
- HackerNoonhackernoon.com/u/pavanchow
- Hubpavanchow.github.io
- Researcher profilepavanchow.gitlab.io