REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
67
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'curl'
disclosed a bug submitted by
b'vovohelo'
b'Integer Overflow in `curl_easy_escape()` may lead to heap buffer overflow and stack memory disclosure on 32-bit platforms'
25 Dec 2025
b'curl'
disclosed a bug submitted by
b'pwnie'
b'Public-suffix cookie injection when libpsl is disabled'
25 Dec 2025
b'curl'
disclosed a bug submitted by
b'strokep'
b'Heap Buffer Over-Read via Malicious SMB Server READ_ANDX Response'
25 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'waloodi109'
b'tabnabbing in roundcube webmail'
24 Dec 2025
b'curl'
disclosed a bug submitted by
b'anonymous_237'
b'HAProxy Connection Reuse leads to IP Spoofing and mTLS Context Smuggling'
23 Dec 2025
b'curl'
disclosed a bug submitted by
b'pwnie'
b'libcurl WebSocket handshake accepts any Sec-WebSocket-Accept'
23 Dec 2025
b'Nextcloud'
disclosed a bug submitted by
b'lauritz'
b'[nextcloud/mail] Blind SSRF to Internal Network via "List-Unsubscribe" SMTP Header when allow_local_remote_servers is allowed'
23 Dec 2025
b'Basecamp'
disclosed a bug submitted by
b'brumbelow'
b'Link unfurling calls out to arbitrary URLs and the private-network guard misses link-local addresses'
22 Dec 2025
b'curl'
disclosed a bug submitted by
b'herdiyanitdev'
b'Functional Regression in Digest Authentication: Failure to handle optional spaces and escaped quotes'
21 Dec 2025
b'curl'
disclosed a bug submitted by
b'herdiyanitdev'
b'A logic error in detect_proxy caused truncation of environment variable names for long protocol schemes.'
21 Dec 2025
b'curl'
disclosed a bug submitted by
b'gaurav0212'
b'Unbounded memory consumption via compressed HTTP responses (gzip/brotli/zstd)'
21 Dec 2025
b'curl'
disclosed a bug submitted by
b'strokep'
b'Heap Buffer Over-Read via Malicious SMB Server READ_ANDX Response'
20 Dec 2025
b'Node.js'
disclosed a bug submitted by
b'sideni'
b'Missing AES-GCM Authentication Tag Validation and Improper Deprecation Handling'
19 Dec 2025
b'Trellix'
disclosed a bug submitted by
b'lemonoftroy'
b'RXSS in https://jp.mcafee.com/apps/mdm/jp/3.0_asp/ '
19 Dec 2025
b'curl'
disclosed a bug submitted by
b'im4x'
b'File URL UNC Path Access (Windows SSRF)'
18 Dec 2025
b'Cosmos'
disclosed a bug submitted by
b'tychebe'
b'Economic DoS (Griefing) on IBC Relayers via `memo` Callback Gas Exploitation'
18 Dec 2025
b'IBM'
disclosed a bug submitted by
b'kanon4'
b'[RCE] Remote Code Execution via React Server Components Vulnerability CVE-2025-55182'
18 Dec 2025
b'curl'
disclosed a bug submitted by
b'anonymous_237'
b'Certificate Pinning Bypass with wolfSSL backend over HTTP/3'
17 Dec 2025
b'curl'
disclosed a bug submitted by
b'badrodin22'
b'Heap buffer overflow in Curl_ipv4_resolve_r due to incorrect buffer alignment and size calculation on AmigaOS'
17 Dec 2025
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'matured_kazama'
b'Second-Order XSS via javascript protocol in MCP Server Portal Apps leads to ATO'
16 Dec 2025
1
...
4
5
6
7
8
...
751
BY DENIS WERNER - @NOBBD -
IMPRESSUM