REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
67
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'curl'
disclosed a bug submitted by
b'rat5ak'
b'CVE-2026-3805: use after free in SMB connection reuse'
11 Mar 2026
b'curl'
disclosed a bug submitted by
b'nobcoder'
b'CVE-2026-3784: wrong proxy connection reuse with credentials'
11 Mar 2026
b'curl'
disclosed a bug submitted by
b'spectreglobalsec'
b'CVE-2026-3783: token leak with redirect and netrc'
11 Mar 2026
b'curl'
disclosed a bug submitted by
b'sabari_n'
b'Connection Reuse Ignores OAuth Bearer Token Mismatch'
10 Mar 2026
b'curl'
disclosed a bug submitted by
b'sabari_n'
b'CURLOPT_UNRESTRICTED_AUTH Dangerous Default Documentation Gap'
10 Mar 2026
b'AWS VDP'
disclosed a bug submitted by
b'locus-x64'
b'Arbitrary Code Execution via Scanner Bypass in **aws-diagram-mcp-server** `exec()` Namespace'
09 Mar 2026
b'Lovable VDP'
disclosed a bug submitted by
b'hossam25'
b'Users can change project visibility which requires high subscription by just changing request body'
09 Mar 2026
b'curl'
disclosed a bug submitted by
b'brewm4ster'
b'LM Challenge-Response Hash Always Sent in SMB Authentication'
09 Mar 2026
b'curl'
disclosed a bug submitted by
b'y_security'
b"In curl's SASL OAUTHBEARER authentication, including the SOH character (0x01) in the username corrupts the message structure."
08 Mar 2026
b'Kubernetes'
disclosed a bug submitted by
b'fisjkars'
b'Injection in path parameter of Ingress-nginx'
07 Mar 2026
b'LinkedIn'
disclosed a bug submitted by
b'safehacker_2715'
b'IDOR to make someone attend or leave an event'
06 Mar 2026
b'LinkedIn'
disclosed a bug submitted by
b'riadalrashed'
b'Blocking a company page admin prevents him from delete paid media admin or edit his roles'
05 Mar 2026
b'Lovable VDP'
disclosed a bug submitted by
b'jdc94'
b'Open Redirect on lovable.dev via redirect parameter leads to phishing attacks'
05 Mar 2026
b'Fastify'
disclosed a bug submitted by
b'onlybugs05'
b'DoS via Unbounded Memory Allocation in sendWebStream on Fastify v5.7.0+ leads to OOM crash when backpressure is ignored'
05 Mar 2026
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b'Missing Access Control in MigrationFile allows attacker to upload files to any Migration'
05 Mar 2026
b'curl'
disclosed a bug submitted by
b'errorbehavior200'
b'SSTI leads to Command injection'
04 Mar 2026
b'curl'
disclosed a bug submitted by
b'deepbluev7'
b'Use after free in hyperfifo example'
03 Mar 2026
b'Omise'
disclosed a bug submitted by
b'0x7ashish'
b'2FA requirement bypass when inviting team members'
28 Feb 2026
b'AWS VDP'
disclosed a bug submitted by
b'h0ne_analyst_94cm4n1'
b'Password Reuse Vulnerability on AWS Sign-in Page via Password Reset Flow leads to Security Policy Violation'
26 Feb 2026
1
2
3
...
754
BY DENIS WERNER - @NOBBD -
IMPRESSUM