Alan Ortega

Alan
Ortega

Cybersecurity

grpc-go CVSS 7.5 Fixed in v1.81.1

Open to junior security roles · Netherlands / Madrid / remote

00

The fallthrough

An authorization check is supposed to deny when it does not match. This one kept looking. It tried the URI SAN, then the DNS SAN, then the certificate's Subject DN — and the Subject DN let it in.

This is the finding, drawn. Nothing else on this site is red.

URI SAN DNS SAN Subject DN The authenticatedMatcher fallthrough A request checks for a URI SAN and finds none, falls through to the DNS SAN and finds none, and falls through again to the certificate Subject DN, which matches — granting access that should have been denied.
No URI SAN — fall through No DNS SAN — fall through Subject DN matched — allowed
01

Findings

01

Google

grpc-go · Open Source VRP

An authentication bypass in gRPC's xDS RBAC engine: the authenticatedMatcher fell through from the URI/DNS SAN to the certificate's Subject DN. Fixed by Google and credited in the release notes.

Fixed · v1.81.1

CVSS 7.5

02

Google

protobuf-go · merged upstream

prototext's RecursionLimit was silently bypassed on the unknown-field skip path: skipValue and skipMessageValue recursed into each other without decrementing it, so deeply nested unknown messages aborted the process with a stack overflow that Go cannot recover from. I reported it and authored the fix, merged after review by the protobuf-go maintainers.

Merged · master

Denial of service

03

Microsoft

MSRC

Withheld until the vendor publishes.

Under review

High

04

NVIDIA

PSIRT · Public Bug Bounty

Withheld until the vendor publishes.

Reproduced · under review

High

Open reports stay at vendor, severity and status. No component, no vulnerability class, no identifier, no bounty figure.

02

The credit

Anyone can claim they found something. This is the part that cannot be claimed: my name, in the release notes of the fix, published by Google.

xds/rbac: Fix a potential authorization bypass caused by incorrectly falling through URI/DNS SANs to Subject Distinguished Name (DN) when matching the authenticated principal name. With this fix, only the first non-empty identity source will be used, as per gRFC A41. (#9111)

Special Thanks: @al4an444

grpc-go v1.81.1 release notes Source
03

Case study

ZeroLogon CVE-2020-1472 CVSS 10.0

The domain controller of the vocational school I attended was missing the August 2020 updates. I demonstrated the impact, stopped at proof, kept no data, reported it immediately, and worked with the school to remediate and harden the environment.

04

Who

Twenty years old, self-taught, based in the Netherlands and able to work from Madrid.

Nobody assigned me any of this. It's simply what I like doing.

Education
HND in Network & Systems Administration (ASIR) ILERNA Online · 2025 — 2027, in progress
Education
Vocational degree in Microcomputer Systems & Networks (SMR) Completed · 2023 — 2025
Experience
Technical Support MOMPALAO, Malta · Mar — May 2025
Experience
Seasonal work while studying Slagharen Theme Park (NL) · El Corte Inglés (ES) · Nov 2024 — Aug 2025
Certifications
Introduction to the Threat Landscape 3.0 Fortinet Training Institute · Apr 2026 Introduction to Cybersecurity Cisco Networking Academy · Apr 2026
06

Hire me

Looking for a junior role in application security, vulnerability research or security engineering.