A public collection of vulnerability-research writeups, methodology notes, and post-disclosure case studies from independent work on HackerOne and Bugcrowd programs. Each writeup leads with how the bug was reached, the source-reading and variant-hunting that generalizes, not just what it was.
Everything here respects coordinated disclosure: findings appear only after the program's window closed, the upstream patch shipped, or the same bug class was published elsewhere with a referenced CVE. No customer data was accessed; test artifacts were cleaned up after submission.