REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'22: FTP wildcard matching decodes server-provided filenames, enabling directory traversal'
08 Sep 2026
b'MariaDB'
disclosed a bug submitted by
b'byteoverride'
b'Stack Buffer Overflow in mariadb-dump quote_name() Allows Malicious Server to Execute Arbitrary Code on Client'
08 Sep 2026
b'MariaDB'
disclosed a bug submitted by
b'pinebudweiser'
b'Out-of-bounds read in MariaDB .frm parsing enables RCE via vtable hijacking'
08 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'49: Cookie-jar save transfers group access to a different GID'
08 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'29: CURLOPT_ISSUERCERT accepts a different-key certificate when issuer metadata collides'
08 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'08: CVE-2026-7009 fix incomplete for AWS-LC: `--cert-status` bypass on SecTrust path'
08 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'Apple SecTrust fallback ignores CURLOPT_CRLFILE, letting a revoked cert pass'
08 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'HTTP Digest nonce reused across an httpshttp scheme change on the same handle'
08 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'54: Rejected HTTP/2 push destroys MIME callback state still used by parent (use-after-free)'
07 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'57: Heap out-of-bounds read in `curl_easy_escape_ccsid()` / `curl_easy_unescape_ccsid()`'
07 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'43: HTTP proxy CONNECT header chooses the `-OJ` filename after a redirect'
07 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'36: HTTP upload resume offset consumed twice after early 307/308 redirect'
07 Sep 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'11: `CURLOPT_FORBID_REUSE` silently lost on multiplexed HTTP/2 connection when the forbidding transfer finishes first'
07 Sep 2026
b'MariaDB'
disclosed a bug submitted by
b'kevin_mizu'
b'MariaDB GRANT PROXY permits unauthorized authentication changes and administrator account takeover'
07 Sep 2026
b'MariaDB'
disclosed a bug submitted by
b'v3rtical'
b'MariaDB: heap buffer overflow in ha_tina::chain_append() lets a low-privileged user crash the server via CSV row deletion'
07 Sep 2026
b'MariaDB'
disclosed a bug submitted by
b'dogeshark'
b'KILL authorization trusts the presented login name instead of the authenticated anonymous account'
07 Sep 2026
b'MariaDB'
disclosed a bug submitted by
b'dogeshark'
b'ACL cache collision lets a role inherit privileges from a same-named socket user'
07 Sep 2026
b'Nextcloud'
disclosed a bug submitted by
b'chinnuy935336'
b'Unauthenticated testing endpoint of notify_push expose internal IP'
05 Sep 2026
b'Nextcloud'
disclosed a bug submitted by
b'cybershinu90'
b'Email Enumeration via Password-Protected Share Identity Verification'
05 Sep 2026
1
2
3
...
776
BY DENIS WERNER - @NOBBD -
IMPRESSUM