REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Essity'
disclosed a bug submitted by
b'matty69v'
b'Pre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit)'
27 Aug 2026
b'Essity'
disclosed a bug submitted by
b'matty69v'
b'Critical SQL Injection WDM API ()'
27 Aug 2026
b'curl'
disclosed a bug submitted by
b'k4rasu_s4ma'
b' curl_share TOCTOU > RCE via Curl_llist _dtor Function Pointer Hijack'
26 Aug 2026
b'Discourse'
disclosed a bug submitted by
b'ahpuh'
b'Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization'
26 Aug 2026
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b'Add labels to arbitrary issues/prs via Memex Bulk Update to compromise github actions label gating '
25 Aug 2026
b'curl'
disclosed a bug submitted by
b'1rhino2'
b'TLS session cache case-folds CA paths and bypasses the active trust profile'
25 Aug 2026
b'curl'
disclosed a bug submitted by
b'subadevan'
b'libcurl Digest/NTLM authentication ignores an explicit Authorization header'
25 Aug 2026
b'8x8'
disclosed a bug submitted by
b'a3z4km3'
b'@jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration)'
25 Aug 2026
b'curl'
disclosed a bug submitted by
b'subadevan'
b'RTSP CRLF injection in libcurl allows CURLOPT_RTSP_* values to inject commands into independent sessions'
24 Aug 2026
b'curl'
disclosed a bug submitted by
b'subadevan'
b'wolfSSL backend disables hostname verification when CURLOPT_SSL_VERIFYPEER is 0'
24 Aug 2026
b'Ruby on Rails'
disclosed a bug submitted by
b'offsetmd'
b'URI scheme validation bypass in ActionText `to_markdown` via user-supplied `<action-text-markdown>` marker tag'
24 Aug 2026
b'Nextcloud'
disclosed a bug submitted by
b'mirachael'
b'Path Traversal in Nextcloud Talk Android Exposes User Credentials and Private Data via FileProvider'
24 Aug 2026
b'curl'
disclosed a bug submitted by
b'accl'
b'Domainless COOKIEFILE cookie leaks to unrelated IP-literal hosts'
21 Aug 2026
b'Monero'
disclosed a bug submitted by
b'lilpeko'
b'Monero GUI OpenAlias DNSSEC-invalid resolution still writes spoofable address into recipient field'
20 Aug 2026
b'Monero'
disclosed a bug submitted by
b'qttps'
b'View-only offline transaction creation bypasses the long-payment-ID privacy block'
20 Aug 2026
b'Monero'
disclosed a bug submitted by
b'fg0x0'
b'HTML Injection in Transaction Confirmation Dialog via Address Book Description Enables UI Spoofing Before Fund Transfer'
20 Aug 2026
b'Monero'
disclosed a bug submitted by
b'qttps'
b'Windows installer grants low-privileged users write access to executable P2Pool directory, enabling local code execution'
20 Aug 2026
b'Monero'
disclosed a bug submitted by
b'qttps'
b'monero:// deeplink parsing accepts tx_amount=(all) and can trigger send-all transaction mode'
20 Aug 2026
b'Monero'
disclosed a bug submitted by
b'k-privacy-enjoyer'
b"Loss of multisig funds through single malicious participant's deliberate deception"
20 Aug 2026
1
2
3
...
773
BY DENIS WERNER - @NOBBD -
IMPRESSUM