Skip to content
View subhanUmer's full-sized avatar

Block or report subhanUmer

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
subhanUmer/README.md

Subhan Umer Farooq

Application Security & Offensive Security Researcher
Web & API pentesting · OAuth / OIDC & identity security · source-code review

Critical CVE Published CVEs SAP Hall of Fame Bugcrowd CTFtime #1 Pakistan OSCP in progress

🌐 Portfolio · 💼 LinkedIn · 🚩 CTFtime · 🛡️ Snyk


I break authentication systems used by millions, then help ship the fixes. My day job is authorized web and API pentesting as a VAPT engineer. The rest of the time I audit open-source auth frameworks and report what I find.

Most of my bugs are the kind a scanner walks straight past: OAuth/OIDC flaws, auth bypasses, broken access control, business-logic abuse. I find them by reading the code and proving them with a working PoC, then writing the fix up the way a developer actually wants to read it.

Published security research

Target Issue Severity Reference
better-auth OAuth refresh-token replay, missing client auth on the refresh grant Critical · CVSS 9.1 CVE-2026-53512 · GHSA-pw9m-5jxm-xr6h
better-auth OIDC alg=none accepted + silent PKCE downgrade High · CVSS 8.7 GHSA-9h47-pqcx-hjr4
n8n (190K★, 100M+ Docker pulls) OAuth authorization bypass, missing state-param ownership check Medium CVE-2026-33720
oauth2-server (Node.js) OAuth2 library flaw, found by manual review Medium · CVSS 5.4 SNYK-JS-OAUTH2SERVER-3009137
SAP Validated server-side finding via source review recognized SAP Security Hall of Fame, May 2026
Twilio (NYSE) Validated finding recognized via HackerOne

Both better-auth findings and the n8n bug are in the same class of work: cross-protocol OAuth/OIDC identity flaws found by reading source, not scanning. On top of the public CVEs, I've got 25+ validated vulnerabilities across public and private bug-bounty programs and invites to 15+ private programs on Bugcrowd.

What I work on

web & api pentesting · oauth / oidc & identity · source-code review · devsecops (sast/sca in ci) · ai/llm app security · credential-exposure threat intel

Tooling: Burp Suite (Autorize, Auth Analyzer, JWT Editor, Turbo Intruder), Semgrep, CodeQL, Nuclei, Frida, testssl.sh · Python · Go · Node/TS · Docker · GitHub Actions

Recognition

🥇 #1-ranked CTF team in Pakistan (Schrödinger Bears, CTFtime) · Black Hat MEA finalist · 1st at AirTech & National CyberMuhafiz 2025 · OSCP in progress


Available for security engagements. Reach me through my portfolio or LinkedIn.

Pinned Loading

  1. security-research security-research Public

    OAuth/OIDC and auth-logic vulnerability research — CVE writeups and PoCs

  2. ctf-writeups ctf-writeups Public

    writeups for all the challenges i have solved in the competitions i attended from 2025

    Python

  3. SecureWeb-Extension SecureWeb-Extension Public

    TypeScript

  4. subhanUmer.github.io subhanUmer.github.io Public

    HTML

  5. CyberSec-Hub CyberSec-Hub Public

    JavaScript 2