REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Ruby on Rails'
disclosed a bug submitted by
b'friedchicken112211'
b'Active Storage Vips Transformer Missing validate_transformation CVE-2025-24293 Incomplete Fix'
30 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'vnyuh'
b'HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)'
30 Jul 2026
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b'GitHub scoped user to server tokens can escape their installation'
29 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'sy2n0'
b'Permission Model: --allow-fs-read/--allow-fs-write radix-tree prefix-boundary over-grant'
29 Jul 2026
b'HackerOne'
disclosed a bug submitted by
b'0v3rw4tch'
b'`exportReportPdf` mutation shows internal Activity'
29 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'yottt'
b'HTTPS Agent PFX object-array key collision allows mTLS client identity reuse across different per-request certificates'
29 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'0xoroot'
b'Permission Model Bypass: `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`'
29 Jul 2026
b'Rocket.Chat'
disclosed a bug submitted by
b'button142857'
b"Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)"
29 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'mistercloudsec'
b'Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh'
28 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'nick_frichette_dd'
b'Non-Production API Endpoints for the Amazon Cloudwatch Fails to Log to CloudTrail Resulting in Silent Permission Enumeration'
27 Jul 2026
b'Rocket.Chat'
disclosed a bug submitted by
b'0jayden'
b'Authentication Bypass via XML Signature Wrapping in SAML SSO'
27 Jul 2026
b'Monero'
disclosed a bug submitted by
b'redlobsterzzz'
b'ZMQ RPC Log Injection and Untrusted Payload Persistence'
24 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'notnotnotveg'
b'AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF'
22 Jul 2026
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b'GitHub user to server tokens can create issues in any public repository'
22 Jul 2026
b'8x8'
disclosed a bug submitted by
b'kyotozzx'
b'connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability'
22 Jul 2026
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b'OAuth redirect uri validation bypass for :proxima_first_party_sync apps'
21 Jul 2026
b'Monero'
disclosed a bug submitted by
b'int0ha_'
b'Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes'
20 Jul 2026
b'Rocket.Chat'
disclosed a bug submitted by
b'olidayw'
b'Stored XSS in Rocket.Chat HTML File Export Unauthenticated Entry via LiveChat'
16 Jul 2026
b'GitHub'
disclosed a bug submitted by
b'vaib25vicky'
b'Able to bypass authorization logic and gain more access then intended'
15 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'mistercloudsec'
b'Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections'
15 Jul 2026
1
...
4
5
6
7
8
...
776
BY DENIS WERNER - @NOBBD -
IMPRESSUM