Stan Shaw
I’m an independent security researcher focused on vulnerability discovery in widely-deployed infrastructure: operating system kernels, hypervisors, and language runtimes. My public work includes a pre-auth remote code execution in nginx’s script engine (CVE-2026-42533), a SQL injection in the Django ORM (CVE-2025-64459), a use-after-free in CPython’s perf_trampoline (Issue #143228), a guest-to-host escape chain in QEMU’s CXL Type 3 mailbox emulation (writeup), a guest-triggered heap out-of-bounds in KVM’s SEV-SNP page-state-change handling (CVE-2026-53360), and an independently-discovered local privilege escalation in the Linux DRM GEM subsystem (writeup). I also publish exploitation analysis of other researchers’ bugs, including a page-cache corruption chain for CVE-2026-31694 in the FUSE readdir cache. Additional findings in hypervisors, browsers and baseband are under coordinated disclosure and will be published here after patches ship.
