Tyler Zars

Vulnerability Researcher & Reverse Engineer

Professional software breaker and hardware bricker; officially, Vulnerability Researcher & Reverse Engineer. Most likely chasing down bugs across whatever architecture is misbehaving, writing proof-of-concepts, and trying to get it patched. Probably reverse engineering another custom Japanese RTOS.

When not staring at disassembly, I'm probably running around behind the scenes of a live sports or eSports production.

Find me online

Public Security Research

Vulnerability research and responsible disclosure of security issues in all sorts of things.

CVE-2026-24228: Unsafe Deserialization in NVIDIA NeMo Framework

CVE

Found an unsafe deserialization issue on Linux builds of NVIDIA's NeMo Framework that a local, low-privileged attacker could use to run arbitrary code. Reported through the Zero Day Initiative and coordinated with NVIDIA PSIRT; fixed in NeMo 2.7.3.

NVIDIA NeMo Deserialization ZDI

CVE-2025-54472: Denial of Service in Apache bRPC

CVE

Discovered an unauthenticated denial of service vulnerability in Apache bRPC that could allow attackers to crash the service using a crafted Redis message.

Apache bRPC DoS C++

CVE-2025-59789: Uncontrolled Recursion in Apache bRPC

CVE

Found that bRPC's json2pb component parsed JSON using rapidjson's default recursive parser with no depth limit, so a deeply nested JSON payload sent to a bRPC server would blow the stack and crash the process.

Apache bRPC DoS C++

Arbitrary File Upload Vulnerability

Fixed

Discovered an arbitrary file upload vulnerability in simple-http-server that could allow attackers to upload files anywhere onto the server. Coordinated with the maintainer for a security release.

HTTP Server File Upload Rust

Authenticated Remote Code Execution on ipTime Routers

Research

Research project demonstrating authenticated remote code execution vulnerabilities. Developed proof-of-concept and documentation for security awareness and testing purposes.

RCE IoT Firmware

Unauthenticated Remote Code Execution in BareIron

Research

Pre-Authenticated Remote Code Execution on embedded targets. Created an developed a PR to help fix the issue.

Embedded IoT Firmware

One Byte Stack Overflow in NMAP

Fixed

Remotely triggerable one-byte stack buffer overflow in Nmap FTP parsers when scanning a malicious server.

Nmap Stack Overflow C

Zero Day Initiative

I also report vulnerabilities through Trend Micro's Zero Day Initiative. Cases are kept confidential while vendors develop fixes, so details for anything still in that pipeline aren't listed here until a patch is released.

Responsible Disclosure

All vulnerabilities were reported through proper channels and coordinated disclosure processes. I believe in working with maintainers and security teams to improve software security for everyone.

Featured Projects

Awesome VR/RE Writeups

A curated list of vulnerability research and reverse engineering writeups, resources, and learning materials for security researchers.

Security Research Reverse Engineering Educational

Space Heroes 2023 CTF Problems

Created challenges for a Capture the Flag competition covering web security, reverse engineering, forensics, and cryptography.

Security CTF Education

Typing Test Game

A typing test game implemented in x86 assembly language using the Irvine library.

Assembly x86 Games

Latency Test Docker for InfluxDB

A Docker container for running a latency test and reporting to InfluxDB and Grafana.

Docker Monitoring DevOps

InControl2 Configuration Downloader

A Python script for downloading configuration files from Peplink InControl2 devices.

Python Networking Automation

Skills

Programming & Development
Python C Rust Bash Git x86/ARM/PowerPC Assembly & Disassembly Cross-Platform Development
Security Research
Vulnerability Research Responsible Disclosure Static & Dynamic Analysis Packet Analysis & Wireshark CVE Coordination
Broadcast Engineering
Live Event Production eSports & Gaming Broadcasts AV Setup & Management Broadcasting Hardware & Software

Get In Touch

Want to collaborate on a project or just say hello? Feel free to reach out through any of these platforms.

Blog

Check out my latest posts at tylzars.github.io

Visit Party Parrot memorial!