I am a PhD student in Systems Security at IMDEA Software Institute, my PhD research is done in collaboration with the European Space Agency. My main interest is in security research, with a focus on fuzzing, network security and the space industry.
- CVE-2025-61910: Uncontrolled Memory Allocation in NASA's ION-DTN Bundle Protocol v7
- CVE-2025-54878: Heap-based Buffer Overflow in NASA CryptoLib
- CVE-2025-8183: NULL Pointer Dereference in µD3TN Bundle Protocol v7
- CVE-2024-54129: Improper Initialization in NASA's ION-DTN Bundle Protocol v7
- CVE-2024-54130: NULL Pointer Dereference in NASA's ION-DTN Bundle Protocol v7
- CVE-2024-10455: Reachable Assertion in µD3TN Bundle Protocol v7
- CVE-2024-12107: Double-free in µD3TN Bundle Protocol v7
- Heap-based Buffer Overflow in NASA HDTN
- Use of Unitialised Variable in NASA HDTN
- Uncontrolled Memory Allocation in NASA HDTN
- Out-of-bounds Read in NASA's ION-DTN Bundle Protocol v6
- Improper Input Validation leads to DoS in NASA's ION-DTN Bundle Protocol v6
- Out-of-bounds Read #2 in NASA's ION-DTN Bundle Protocol v6
- Uncaught Exception leading to DoS in LibreCube python-spacepacket #Fixed
*All issues were privately reported to the affected maintainers in accordance with responsible-disclosure guidelines.
HackerOne: sahave
| Program | Issue Type | Reward |
|---|---|---|
| LaunchDarkly | Out-of-bounds read | $1,250 |
| LaunchDarkly | Remote DoS | $150 |
-
📄 Fuzzing Space Communication Protocols
S. Havermans, L. Baumgärtner, J. Roberts, M. Wallum, and J. Caballero
Workshop on the Security of Space and Satellite Systems (SpaceSec), 2025
[Paper] [Scholar] -
📄 Differential Testing of Bundle Protocol v7 Implementations: A Preliminary Report
S. Havermans, L. Baumgärtner, M. Wallum, and J. Caballero
Security for Space Systems Conference (3S), 2025
[Paper] [Scholar]
