[Sample deliverable]
See the format Stella uses for private-audit deliverables.
This sample shows the format Stella uses for selective private audits. It is built from a published Mozilla bug-bounty disclosure credited to Haruto Kimura (Stella) — CVE-2026-6766, an integer underflow in Firefox NSS that produced a wild-address write reachable from any remote QUIC peer. The technical content is real; the private-engagement framing is an illustrative deliverable structure.
[What's inside]
- Cover and engagement summary
- Executive summary (1 page)
- Audit scope and methodology (1 page)
- Finding writeup with reproducible PoC, ASAN output, and source-citation validation (2 pages)
- Patch guidance and validation checklist (1 page)
- Coordinated disclosure timeline and vendor coordination (1 page)
PDF · 7 pages · ~17 KB
Private-audit reports are delivered under NDA. Request a pilot to discuss applying this deliverable format to your codebase.