About PatchLeaks

About PatchLeaks & the author

PatchLeaks is an independent CVE exploit database and patch-diff vulnerability research project. Every advisory is authored and human-reviewed by Huseyn Gadashov (OWASP), with AI-assisted drafting used only for speed-to-publish on the technical write-up.

About the author

Huseyn Gadashov (aka Dzn) is an application security researcher focused on vulnerability research, exploit development, and patch-diff analysis. He is affiliated with OWASP and publishes primary research on CVE root causes, proof-of-concept exploits, and remediation guidance through PatchLeaks.

Areas of expertise

  • Application security & vulnerability research
  • Patch-diffing & root-cause analysis across 41,000+ open-source projects in 11 programming languages
  • Proof-of-concept exploit development
  • Static analysis & sink-rule generation
  • WordPress plugin security & zero-day discovery

About PatchLeaks

PatchLeaks takes a patch commit (or a CVE identifier), diffs it against the pre-patch source, identifies the vulnerable sink and the minimal reproducer path, and publishes a structured advisory with:

  • CVE identifier and affected product / versions
  • Root-cause analysis derived from the upstream patch diff
  • Proof-of-concept exploit breakdown
  • Remediation and patched-version guidance
  • Cross-links to NVD and the underlying automated analysis

The site runs on a fully self-hosted Go backend at pwn.az, with no third-party tracking, no ad network, and no paywalls. Content is published under CC BY 4.0.

Editorial policy

  • Every advisory has a named human reviewer. AI-generated drafts are never published without explicit review by the author.
  • Every claim cites a primary source. Writeups link back to the upstream patch commit, NVD entry, and/or the originating advisory.
  • Every change is timestamped. Publication and modification dates are emitted in article metadata and in the sitemap.
  • Corrections are explicit. Material corrections are noted in-line with the revision date.

Contact & responsible disclosure

For security issues on PatchLeaks itself, see our security.txt. For CVE-specific questions or editorial requests, email [email protected].