First-Party Attribution A+ · 11 receipts
HashiCorp — Consul
CVE-2026-19017A+
“CVE-2026-19017 was reported to HashiCorp by Kai Aizen / SnailSploit (‘The Jailbreak Chef’).”
vendor / upstream
First-party HashiCorp security advisory. Gold-standard receipt.
Kubernetes — ingress-nginx
CVE-2026-3288A+
“This vulnerability was reported by Kai Aizen.”
vendor / upstream
Kubernetes Security Response Committee acknowledgement.
Symfony / Twig
CVE-2026-46627A+
“We would like to thank Kai Aizen (Snailsploit) for reporting the issue.”
vendor / upstream
First-party Symfony security advisory.
Jenkins — Assembla / Contrast Plugins
SECURITY-3692 · SECURITY-3697A+
Jenkins thanks Kai Aizen (SnailSploit) for discovering/reporting four issues.
project security advisory
One first-party advisory credits four separate security issues.
Jenkins — Sauce OnDemand Plugin
CVE-2026-70445A+
“dyingman1 … and independently, Kai Aizen, SnailSploit”
project security advisory
Especially strong: the project explicitly records an independent discovery.
Apache Airflow — Core
CVE-2026-30911A+
“Credit: Kai Aizen (finder)”
upstream security mailing list
Apache security disclosure carried through oss-security.
Apache Airflow — Databricks Provider
CVE-2026-32794A+
“Credit: Kai Aizen (reporter)”
upstream security mailing list
Second distinct Apache Airflow attribution.
Oracle — Product Security
CVE-2026-61308A+
Oracle’s August 2026 Critical Security Patch Update lists “Kai Aizen : CVE-2026-61308” in its contributor credits.
vendor cpu
Enterprise-vendor security credit alongside established security research organizations.
ddev — GitHub Advisory
CVE-2026-32885A+
“Credit: Kai Aizen (SnailSploit) — Adversarial AI & Security Research.”
upstream advisory
GitHub Advisory Database entry published from the ddev project.
PraisonAI — GitHub Advisory
CVE-2026-55528A+
“Credit: Kai Aizen — SnailSploit (@SnailSploit).”
upstream advisory
Project-owned GitHub Security Advisory.
vLLM — GitHub Advisory
CVE-2026-54236A+
“Researcher: Kai Aizen — SnailSploit (@SnailSploit).”
upstream advisory
Upstream advisory explicitly identifies the researcher.