Yehia Ezzat
0xSemizzz Security researcher and computer science student. Vulnerability research, open source security, and low-level systems.
01
Projects
CVE-2026-18649: Unbounded Memory Growth
GStreamer RTP Depayloader
A remote, unauthenticated denial of service in GStreamer's H.264 and H.265 RTP depayloaders, where FU-A fragment reassembly had no size limit. Assigned CVE-2026-18649.
CVE-2026-92162: Flatpak System Helper Path Traversal
Flatpak DeployAppstream arch traversal
A path traversal in the Flatpak system helper where an unvalidated arch string in DeployAppstream lets an active local user make the root helper create directories at an arbitrary path, chaining into a local root file write. Assigned CVE-2026-92162 and GHSA-v2gw-v9h5-9q4x.
Vonnis
Offline script triage, measured against real corpora
A script triage engine that reads a suspicious PowerShell or shell script and answers, in plain English, whether running it is a bad idea. 111 deterministic YAML detection rules, no API key and no network for the verdict, and a measurement harness that scores the rules against 2,526 real package maintainer scripts and 1,862 Atomic Red Team tests.
02
Blog
03
About
- Based in
- Egypt
- Studying
- Computer Science, The British University in Egypt
- Working on
- Vulnerability research, open source security
I'm Yehia Ezzat, an Egyptian Computer Science student at The British University in Egypt (BUE) with an interest in vulnerability research, open source security, and low-level systems.
I spend my time researching vulnerabilities in open source software, developing security tools, and learning how complex software systems work and fail. I have worked on vulnerability research in open source projects such as GStreamer, including responsible disclosure and CVE research.
My interests currently span areas such as hypervisors, web browsers, compilers, operating systems, and other low-level systems. I am still exploring these areas to find where I can contribute the most as a security researcher.
Currently reading about
- Kernel Security
- Linux
- Browser Security
- Container Security
- Compiler Research
- Reverse Engineering
- Memory Corruption
- Fuzzing