No Vuln researcher

Diego Melo
Offensive security researcher · Founder
Offensive security researcher with a track record in international bug bounty programs (U.S. Department of Defense, eToro, Bitso, Hostinger). Founder of No Vuln. Focused on identity vulnerabilities (OAuth, SAML, JWT) and business logic.
Research focus
- Identity and authentication — OAuth 2.0 / OIDC, SAML XSW, JWT (algorithm confusion, JKU SSRF), MFA bypass, ATO chains
- API security — BOLA, BFLA, BOPLA, mass assignment, GraphQL introspection abuse, alias overloading
- Business logic — HTTP/2 race conditions, state machine abuse, business logic bypass, broken assumptions in payment flows
- SSRF chains — exploitation via webhooks, DNS rebinding, gopher to Redis/Memcached, cloud metadata (AWS/GCP/Azure)
- HTTP request smuggling — CL.TE, TE.CL, HTTP/2 single-packet, browser-powered desync
Published articles
Jun 10, 2026 · Guide
Grey Box Pentest Guide 2026: Why It's the Default Choice
Jun 09, 2026 · Vulnerability
7-Step Exploit Chain to Full SaaS Admin Takeover
Jun 07, 2026 · Guide
Black Box Pentest Guide 2026: When to Use It and When Not To
May 24, 2026 · Guide
Black Box vs Grey Box vs White Box Pentest: Which to Choose?
May 23, 2026 · Vulnerability
Race Condition in Payments: The Double-Refund Bug
May 22, 2026 · Vulnerability
JWT alg:none Is Still in Production in 2026. Here's How
May 21, 2026 · Vulnerability
BOLA in Fintech: One Endpoint Leaks Every Tenant
May 07, 2026 · Compliance
Why Legal LGPD Compliance Isn't Enough for SaaS and Apps
May 07, 2026 · Guide
Is Your SaaS Really Secure? 9 Uncomfortable Truths for 2026
May 07, 2026 · Market
10 Best Pentest Companies in Brazil (2026) Compared
May 06, 2026 · Market
In-House vs Outsourced Pentest for Fintechs (2026)
May 05, 2026 · Market
Pentest Cost by SaaS Size in Brazil: 2026 Benchmarks by MRR
May 01, 2026 · Guide
LGPD Compliance for SaaS, Apps and Websites: 2026 Guide
May 01, 2026 · Guide
Data Breach in Brazil: LGPD Fines and How to Avoid Them
May 01, 2026 · Guide
Pre-Launch Security Checklist: 12 Must-Haves for SaaS & Apps
Apr 30, 2026 · Guide
Website or SaaS Hacked? What to Do in the First 24 Hours
Apr 29, 2026 · Guide
Developer, Consultant or Firm: Who Should Secure Your SaaS?
Apr 28, 2026 · Guide
Is My Platform Secure? 9 Warning Signs for SaaS and Fintech
Apr 26, 2026 · Vulnerability
BOLA, BOPLA and BFLA: The 3 Flaws That Rule APIs in 2026
Apr 22, 2026 · Vulnerability
OAuth Account Takeover in SaaS: 5 Patterns Dominating 2026
Apr 20, 2026 · Compliance
LGPD Article 46: 7 Technical Measures the ANPD Expects
Apr 18, 2026 · Market
Pentest vs Security Audit: What Your SaaS Needs in 2026
Apr 15, 2026 · Market
How Much Does a Pentest Cost in Brazil? 2026 Price Ranges
Work with No Vuln
Real adversarial research, under contract.
In-depth pentesting with the same methodology described in our articles. Request a proposal — mutual NDA within 24h.
Talk to a researcher