Who are we?
HTTPVoid is an application-security research team led by Rahul Maini and Harsh Jaiswal. Writeups here cover our own CVEs alongside deep dives where we reverse and weaponise public n-days from advisories or patch diffs.
Rahul and I (Harsh) have known each other since 2014. We met on Facebook, back when random groups there ran little hacking challenges, and kept collaborating here and there whenever something looked interesting. Over the years it became clear we liked the same corner of the craft: reading code, reading other people’s research and novel bugs, and learning new stuff along the way. That’s where most of our time went: reversing CVEs and digging up new bugs in open-source projects and enterprise software, together.
In 2021 we set up this blog as a place to put that work under one name. Not long after, we both joined ProjectDiscovery as researchers, and a lot of what we published there is cross-posted here. Treat this site as the archive of our work together.
In 2025 I (Harsh) left PD to co-found Hacktron AI. A few months later Rahul decided he wanted to join and work in the evolving AI-based security space, left PD, and joined Hacktron as a researcher. Rahul spends most of his time on research. I still do some, but most of mine now goes into product and research.
Posts
-
Remote Code Execution in DELMIA Apriso
-
Authentication Bypass to RCE in Versa Concerto
-
CVE-2025-4427/4428 : Ivanti EPMM Remote Code Execution - Technical Analysis
-
IngressNightmare: Unauth RCE in Ingress NGINX (CVE-2025-1974)
-
CVE-2024-53991 - Discourse Backup Disclosure: Rails send_file Quirk
-
GitHub Enterprise SAML Authentication Bypass (CVE-2024-4985 / CVE-2024-9487)
-
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409)
-
Zimbra - Remote Command Execution (CVE-2024-45519)
-
Hacking Apple - SQL Injection to Remote Code Execution
-
Hello Lucee! Let us hack Apple again?
-
Adobe ColdFusion Pre-Auth RCE(s)
-
CVE-2023-36934 Analysis: MOVEit Transfer SQL Injection
-
Ruby Deserialization - Gadget on Rails
-
Circumventing Browser Security Mechanisms For SSRF
-
Hacking Google Drive Integrations
-
CVE-2021-26084 - Remote Code Execution on Confluence Servers
-
Path traversal in Ruby's Tempfile and mktmpdir on Windows
-
Finding 0day to hack Apple
subscribe via RSS