No Vuln researcher

Diego Melo — Offensive security researcher · Founder

Diego Melo

Offensive security researcher · Founder

Offensive security researcher with a track record in international bug bounty programs (U.S. Department of Defense, eToro, Bitso, Hostinger). Founder of No Vuln. Focused on identity vulnerabilities (OAuth, SAML, JWT) and business logic.

Research focus

  • Identity and authentication — OAuth 2.0 / OIDC, SAML XSW, JWT (algorithm confusion, JKU SSRF), MFA bypass, ATO chains
  • API security — BOLA, BFLA, BOPLA, mass assignment, GraphQL introspection abuse, alias overloading
  • Business logic — HTTP/2 race conditions, state machine abuse, business logic bypass, broken assumptions in payment flows
  • SSRF chains — exploitation via webhooks, DNS rebinding, gopher to Redis/Memcached, cloud metadata (AWS/GCP/Azure)
  • HTTP request smuggling — CL.TE, TE.CL, HTTP/2 single-packet, browser-powered desync

Published articles

Work with No Vuln

Real adversarial research, under contract.

In-depth pentesting with the same methodology described in our articles. Request a proposal — mutual NDA within 24h.

Talk to a researcher