News

Latest news & articles

Our public vulnerability disclosure record
21 August 2026

A consolidated index of the CVEs and vendor acknowledgements published under the Isopach name since 2020, covering network equipment, desktop software, mobile applications, and open-source libraries.

ONLYOFFICE credits Isopach for coordinated disclosure on HackerOne
15 July 2026

ONLYOFFICE named Isopach on its corporate blog for the volume of security reports submitted through its HackerOne programme. The individual reports remain under the programme's disclosure terms.

Stack Overflow via Cyclic Style Chain in docx4j leads to Denial of Service (CVE-2026-53752)
07 July 2026

docx4j resolved OpenXML style inheritance without cycle detection, so a Word document whose styles referenced each other in a loop could exhaust the stack of any service that parsed it. Fixed in 11.5.14 and credited to Isopach.

Precise GPS Location Disclosure in HelloTalk (CVE-2020-25900)
05 June 2026

HelloTalk stored full-precision GPS coordinates in an unencrypted local database even for users who had chosen to share only their country or city, and copied those coordinates onto other users' devices. The CVE record is now public.

We are now a licensed Penetration Testing Service provider!
13 January 2023

As of today, the Cyber Services Regulation Office of Singapore has officially issued us our Penetration Testing License and we can commence official testing in Singapore.

essential