Private beta · 2026

Multi-source static security analysis for production codebases.

What it does

Pardes combines LLM cross-validation with deterministic static detectors to find real vulnerabilities in mid-to-large codebases without the false-positive flood of single-source tools.

Recent results

Pardes-generated findings filed through coordinated disclosure:

7 disclosures filed
12 codebases audited
3 novel CWE patterns
Identity / OAuth 2026-05-12
Reflected XSS via OAuth state in front-channel logout (EndSessionUtils) — Critical, CVSS 9.3
Janssen jans-auth-server GHSA-vxgw-mxhf-2m6f ↗
Identity / OAuth 2026-05-12
SSRF via sector_identifier_uri in Dynamic Client Registration — High, CVSS 7.5
Janssen jans-auth-server GHSA-9qw4-gwgf-3q27 ↗
Identity / OAuth 2026-05-12
SSRF via request_uri in consent rendering (AuthorizeAction) — Moderate, CVSS 6.5
Janssen jans-auth-server GHSA-8gmm-83qv-w67g ↗
Identity / OAuth 2026-06-22
Account takeover via email auto-linking that skips IdP-side email verification (CWE-287) — Moderate, CVSS 4.8
ZITADEL GHSA-992q-9gwp-7r79 / CVE-2026-56666 ↗
Library hardening 2026-05-12
Request Object accepts alg=none when client omits request_object_signing_alg registration
ory/fosite #876 ↗
Library hardening 2026-05-12
jsonx.EmbedSources default scheme allowlist permits file:// and unfiltered http(s)
ory/x #881 ↗
Upstream PR 2026-05-03
get_peer_cred returns root credentials on espidf/vita/hurd
tokio-rs/tokio #8111 ↗

Additional findings against identity, OAuth, and OIDC providers are under coordinated disclosure with the affected vendors. Track record updated as embargoes lift.

Status

Currently in private beta with security teams in production SaaS, internal platforms, and bug bounty programs.

Early access

If you run a security program, a platform engineering team with security responsibility, or a bug bounty research practice, drop a note. Replies usually within a couple of days.

Vulnerability reports + responsible disclosure: [email protected]

Inquiries: [email protected]