REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
67
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Kubernetes'
disclosed a bug submitted by
b'fisjkars'
b'Injection in path parameter of Ingress-nginx'
07 Mar 2026
b'LinkedIn'
disclosed a bug submitted by
b'safehacker_2715'
b'IDOR to make someone attend or leave an event'
06 Mar 2026
b'LinkedIn'
disclosed a bug submitted by
b'riadalrashed'
b'Blocking a company page admin prevents him from delete paid media admin or edit his roles'
05 Mar 2026
b'Lovable VDP'
disclosed a bug submitted by
b'jdc94'
b'Open Redirect on lovable.dev via redirect parameter leads to phishing attacks'
05 Mar 2026
b'Fastify'
disclosed a bug submitted by
b'onlybugs05'
b'DoS via Unbounded Memory Allocation in sendWebStream on Fastify v5.7.0+ leads to OOM crash when backpressure is ignored'
05 Mar 2026
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b'Missing Access Control in MigrationFile allows attacker to upload files to any Migration'
05 Mar 2026
b'curl'
disclosed a bug submitted by
b'errorbehavior200'
b'SSTI leads to Command injection'
04 Mar 2026
b'curl'
disclosed a bug submitted by
b'deepbluev7'
b'Use after free in hyperfifo example'
03 Mar 2026
b'Omise'
disclosed a bug submitted by
b'0x7ashish'
b'2FA requirement bypass when inviting team members'
28 Feb 2026
b'AWS VDP'
disclosed a bug submitted by
b'h0ne_analyst_94cm4n1'
b'Password Reuse Vulnerability on AWS Sign-in Page via Password Reset Flow leads to Security Policy Violation'
26 Feb 2026
b'curl'
disclosed a bug submitted by
b'knickers'
b'Integer Overflow in curl_multi_get_handles() Leading to Heap Buffer Overflow'
26 Feb 2026
b'curl'
disclosed a bug submitted by
b'davkor'
b'RTSP RTP Interleaved Parser Assertion Failure (Zero-Length RTP Payload)'
26 Feb 2026
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'matured_kazama'
b'AI Playground XSS to steal user-chat messages and access to connected MCP Server'
26 Feb 2026
b'curl'
disclosed a bug submitted by
b'shan_nandi'
b'Able to bypass HSTS using trailing dot'
26 Feb 2026
b'curl'
disclosed a bug submitted by
b'pelioro'
b'Curl Telnet Handler Buffer Overflow'
26 Feb 2026
b'PortSwigger Web Security'
disclosed a bug submitted by
b'zorixu'
b'HTML Injection in DAST Trial Request Form Confirmation Email PortSwigger'
26 Feb 2026
b'Mars'
disclosed a bug submitted by
b'xgoon'
b'Publicly accessible `` endpoint exposing internal user identifiers and email addresses'
24 Feb 2026
b'Mars'
disclosed a bug submitted by
b'0xr2r'
b'CVE--35813 in '
24 Feb 2026
b'Mars'
disclosed a bug submitted by
b'prakhar0x01'
b'Sensitive information exposed at [] via /export_panelists_to_xlsx endpoint'
24 Feb 2026
1
2
3
...
754
BY DENIS WERNER - @NOBBD -
IMPRESSUM