PatchLeaks is an independent CVE exploit database and patch-diff vulnerability research project. Every advisory is authored and human-reviewed by Huseyn Gadashov (OWASP), with AI-assisted drafting used only for speed-to-publish on the technical write-up.
About the author
Huseyn Gadashov (aka Dzn) is an application security researcher focused on vulnerability research, exploit development, and patch-diff analysis. He is affiliated with OWASP and publishes primary research on CVE root causes, proof-of-concept exploits, and remediation guidance through PatchLeaks.
Areas of expertise
- Application security & vulnerability research
- Patch-diffing & root-cause analysis across 41,000+ open-source projects in 11 programming languages
- Proof-of-concept exploit development
- Static analysis & sink-rule generation
- WordPress plugin security & zero-day discovery
About PatchLeaks
PatchLeaks takes a patch commit (or a CVE identifier), diffs it against the pre-patch source, identifies the vulnerable sink and the minimal reproducer path, and publishes a structured advisory with:
- CVE identifier and affected product / versions
- Root-cause analysis derived from the upstream patch diff
- Proof-of-concept exploit breakdown
- Remediation and patched-version guidance
- Cross-links to NVD and the underlying automated analysis
The site runs on a fully self-hosted Go backend at pwn.az, with no third-party tracking,
no ad network, and no paywalls. Content is published under
CC BY 4.0.
Editorial policy
- Every advisory has a named human reviewer. AI-generated drafts are never published without explicit review by the author.
- Every claim cites a primary source. Writeups link back to the upstream patch commit, NVD entry, and/or the originating advisory.
- Every change is timestamped. Publication and modification dates are emitted in article metadata and in the sitemap.
- Corrections are explicit. Material corrections are noted in-line with the revision date.
Contact & responsible disclosure
For security issues on PatchLeaks itself, see our security.txt. For CVE-specific questions or editorial requests, email [email protected].