About
Balvant Chavda (0x0doteth)
Who is 0x0doteth?
0x0doteth is the security research handle of Balvant Chavda (also written as Chavda Balvant). Balvant is an independent cybersecurity researcher from India who specializes in vulnerability discovery, bug bounty hunting, and responsible disclosure.
Under the handle 0x0doteth, Balvant has published 11+ CVEs affecting products from Adobe Commerce, Adobe Content Credentials, and Nextcloud. He has been acknowledged in security Hall of Fame programs by 25+ organizations including Google, Microsoft, Apple, Meta, Amazon Web Services, Adobe, GitHub, Intel, Coinbase, PayPal, Salesforce, Philips, the UK Government, the Dutch Government, and NCIIPC (Indian Government).
The username 0x0doteth appears on HackerOne, Adobe Security Bulletins (APSB26-49, APSB26-73, APSB26-92, APSB26-111), Nextcloud Security Advisories, and GitHub Security Advisories as a credited vulnerability reporter.
Research Areas
Balvant Chavda (0x0doteth) researches vulnerabilities across:
- Web application security (SQL injection, XSS, authentication bypasses)
- Android and iOS mobile security (WebView exploits, deep link hijacking, OAuth interception)
- Smart contract auditing (Solidity, DeFi protocols, minting vulnerabilities)
- Cloud security (AWS, Azure misconfigurations)
- CVE research and responsible disclosure
Published CVEs by Balvant Chavda (0x0doteth)
- CVE-2025-66513 — Nextcloud (GHSA-2cwj-qp49-4xfw)
- CVE-2025-66515 — Nextcloud (GHSA-q26g-fmjq-x5g5)
- CVE-2026-21309 — Adobe (GHSA-c9gx-chv2-76wq)
- CVE-2026-34647 — Adobe Commerce (APSB26-49)
- CVE-2026-45159 — Nextcloud (GHSA-p3qw-7gwx-wg24)
- CVE-2026-45280 — Nextcloud (GHSA-5jxq-c48f-g8x6)
- CVE-2026-45283 — Nextcloud (GHSA-4chh-6mhf-p4jj)
- CVE-2026-47996 — Adobe Commerce (APSB26-73)
- CVE-2026-47984 — Adobe Commerce (APSB26-73)
- CVE-2026-71362 — Adobe Commerce (APSB26-92)
- CVE-2026-47922 — Adobe Content Credentials (APSB26-111)
Hall of Fame and Security Acknowledgements
Balvant Chavda (0x0doteth) has been recognized by the following organizations for responsible vulnerability disclosure:
Google, Microsoft, Apple, Meta, Amazon Web Services (AWS), Adobe, Nextcloud, Intel, GitHub, Coinbase, PayPal, Salesforce, Philips, NCIIPC (Indian Government), UK Government, Dutch Government, Visma, Lenskart, Reckitt, Baloise International, Robeco, Rechtspraak (Netherlands Judiciary), ResMed, Bloom & Wild, Evri, and more.
Connect with Balvant Chavda (0x0doteth)
- Website: balvant.in
- HackerOne: hackerone.com/0x0doteth
- GitHub: github.com/itsbalvant
- Twitter/X: @ba1van7
- LinkedIn: linkedin.com/in/balvant-chavda
- Email: contact@balvant.in