Profile Picture

Seokchan Yoon

Offensive Web Security Researcher

Security Contributor of GitHub, Python, Django, Airflow, Ruby, Ruby-on-Rails, Java Spring

Education

March 2020 - Present

Bachelor's Degree in Computer Science & Engineering (In Progress)

KyungHee University

July 2017 - May 2018

Completed Vulnerability Analysis Track

Best of the Best, Korean Next-Generation Security Leader Training Program

March 2017 - February 2020

Graduated from Dept. of Hacking Defense

Korea Digital Media Highschool

Work Experience

July 2025 - Present 5 months

Security Team Member (Volunteer)

Airflow Security Team, Apache Software Foundation USA

  • • Reviewing and addressing security vulnerabilities in Apache Airflow
  • • Collaborating with the open-source community
  • • Maintaining the security posture of the project in accordance with ASF guidelines
April 2025 - Present 8 months

Security Researcher

Zellic.io USA

  • • Security audit of Web2 components within the Web3 ecosystem
September 2023 - March 2025 1 year 6 months

Unit [REDACTED], Private [REDACTED]

Research Institute under the Ministry of National Defense, Korea

  • • Research and development of [REDACTED]
July 2020 - June 2023 3 years

R&D / Proactive Response Team, Security Engineer

STEALIEN

  • • Web penetration testing
  • • Development and operation of educational systems (Cyber Drill System, Django + React) and CTF
  • • Development and maintenance of internal tools, technical blogs, deployment systems, and other infrastructure

CTF Awards

2025 CCE (Cyber Conflict Exercise)

Finalist
General Division

- hosted by National Intelligence Service, Korea

- Team: 경희대미남해커들 (KHU's hansome hackers)

2025 DEF CON CTF 33

Finalist

- hosted by Nautilus Institute

- Team: Cold Fusion

🏆 2024 White Hat Contest

Soldier Division

- hosted by Ministry of National Defense, Korea

- Team: 키보드워리어플랫폼 (Keyboard Warrior Platform)

1st, Korea Defense Minister Award

2023 CODEGATE

Finalist
University Division

- hosted by Ministry of Science and ICT, Korea

- Team: 경희대미남해커들 (KHU's hansome hackers)

2022 CODEGATE

Finalist
University Division

- hosted by Ministry of Science and ICT, Korea

- Team: 경희대미남해커들 (KHU's hansome hackers)

🏆 2022 CCE (Cyber Conflict Exercise)

Public Institution Sector Division

- hosted by National Intelligence Service, Korea

- Team: resilience

2nd, Korea Security Research Institute Director Award

🏆 2022 HACKTHEON SEJONG National University Cybersecurity Competition

- hosted by Sejong Special Self-Governing City, Korea

- Team: 라임도둑 (Lime Thief)

6st, Korea Security Research Institute Director Award

🏆 2021 CCE (Cyber Conflict Exercise)

Public Institution Sector Division

- hosted by National Intelligence Service, Korea

- Team: resilience

2nd, Korea Security Research Institute Director Award

🏆 2019 Cyber Operations Challenge

Student Division

- hosted by Ministry of National Defense, Korea

- Team: 윤석찬TV구독과좋아요알림설정까지

2nd, Korea Cyber Command Award

🏆 2018 Cybersecurity Competition

Individual Preliminary Round

- hosted by Ministry of Education, Korea

1st, SWU President Award

🏆 2018 Cybersecurity Competition

Team Finals

- hosted by Ministry of Education, Korea

- Team: 문시우1인팀 (munsiwoo 1-person team)

1st, Education Minister Award

🏆 2017 Cybersecurity Competition

Team Finals

- hosted by Korea Education and Research Information Service

- Team: 4-day exploit

1st, KERIS Director Award

Disclosed Vulnerabilities

Python Python

CVE-2024-7592

Denial of Service
Internals

A vulnerability in Python allows quadratic complexity parsing when handling cookies containing backslashes, potentially leading to performance degradation.

Django Django

CVE-2023-36053

Regular Expression Denial of Service
Internals

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, `EmailValidator` and `URLValidator` are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

Django Django

CVE-2024-24680

Denial of Service
Templates

A vulnerability in the Django `intcomma` template filter could lead to a potential denial of service if certain crafted inputs are processed.

Django Django

CVE-2024-27351

Regular Expression Denial of Service
Utilities

A vulnerability in Django's `Truncator.words()` function may allow a ReDoS attack under certain circumstances.

Django Django

CVE-2024-21520

Cross-Site Scripting
Rest Framework

The browserable API of the Django Rest Framework is vulnerable to cross-site scripting due to improper sanitization of user-supplied inputs.

Django Django

CVE-2024-41991

Denial of Service
Utilities

A vulnerability in Django's `urlize` function and `AdminURLFieldWidget` could allow for a denial of service under specific crafted input conditions.

Django Django

CVE-2024-53908

SQL Injection
Database

A vulnerability in the `HasKey` function in Django when using Oracle databases may allow a potential SQL injection.

Django Django

CVE-2025-48432

Log Injection
Internal Logging

Internal HTTP response logging used request.path directly, allowing control characters (e.g. newlines or ANSI escape sequences) to be written unescaped into logs.

Django Django

CVE-2025-64458

Denial of Service
HTTP Responses

Python's NFKC normalization is slow on Windows. As a consequence, Django's HttpResponseRedirect, HttpResponsePermanentRedirect, and the redirect() shortcut were subject to a potential denial-of-service attack via inputs containing a very large number of Unicode characters (follow-up to CVE-2025-27556).

FastAPI FastAPI / Starlette

CVE-2025-62727

Denial of Service
starlette.responses.FileResponse

Found an O(n^2) complexity denial of service in Starlette's FileResponse Range header merging that lets an attacker exhaust resources with a single crafted request.

Apache Apache Airflow

CVE-2024-39877

Code Execution
Scheduler

A vulnerability in Apache Airflow's scheduler allows DAG authors to execute arbitrary code, potentially compromising the scheduler node.

Apache Apache Airflow

CVE-2024-39863

Cross-Site Scripting
Web Interface

Improper sanitization in Apache Airflow's web interface could lead to a cross-site scripting vulnerability.

Apache Apache Airflow

CVE-2024-45034

Code Execution
Scheduler

Authenticated DAG authors in Apache Airflow can execute arbitrary code on scheduler nodes, leading to potential system compromise.

Ruby Ruby

CVE-2024-41123

Denial of Service
REXML

Vulnerabilities in Ruby's REXML library allow attackers to cause a denial of service by crafting malicious XML inputs.

Ruby Ruby on Rails

CVE-2024-47887

Regular Expression Denial of Service
Action Controller

Ruby on Rails' Action Controller is vulnerable to a potential regular expression denial of service when handling HTTP token authentication.

Ruby Ruby on Rails

CVE-2024-41128

Regular Expression Denial of Service
Action Dispatch

A vulnerability in Rails' Action Dispatch may allow a regular expression denial of service when filtering query parameters.

Java Java Spring

CVE-2024-38809

Denial of Service
Framework

Spring Framework is vulnerable to a potential denial of service caused by a crafted conditional HTTP request.

GitHub GitHub

HackerOne #2646500

Denial of Service
GitHub & GitHub Enterprise

GitHub is vulnerable to a potential denial of service caused by a malicously crafted HTTP request.

NAVER NAVER

NBB-1126

Stored XSS
NAVER service

NAVER is vulnerable to a stored-xss caused by a crafted payload.

NAVER NAVER

NBB-1143

SQL Injection
NAVER service

NAVER is vulnerable to a SQL injection caused by a crafted payload.

NAVER NAVER

NBB-1260

Stored XSS
NAVER service

NAVER is vulnerable to a stored XSS caused by a crafted payload.

Talks

2024

" Django Framework from a Hacker's Perspective " (in Korean)

PyCon KR 2024

2023

" Analysis of Django Framework N-day Vulnerabilities and Secure Coding Guide " (in Korean)

CODEGATE 2023

2023

" Django Framework 1-day Analysis " (in Korean)

26th Hacking Camp

2022

" Bug Cases and Secure Coding in Modern Web Services " (in Korean)

STEALIEN Security Seminar

Blogs