REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'AWS VDP'
disclosed a bug submitted by
b'sh3d0w'
b'GitHub Retired UsernameTakeover From [aws/]'
03 Aug 2026
b'Rocket.Chat'
disclosed a bug submitted by
b'howtoplay'
b'Unauthenticated Path Traversal (LFI) via /custom-sounds/ when CustomSounds uses FileSystem storage'
03 Aug 2026
b'curl'
disclosed a bug submitted by
b'dark_river'
b'SMTP CRLF injection in custom SMTP recipient operand allows additional SMTP commands after authentication'
03 Aug 2026
b'Liberapay'
disclosed a bug submitted by
b'its9me'
b'Unauthenticated team "income/payments" export ignores donor privacy settings (hide_giving, hide_from_lists) and uses frozen visibility, exposing donat'
01 Aug 2026
b'Node.js'
disclosed a bug submitted by
b'nadav0077'
b'HTTP Request Smuggling via Connection: close<TAB> in Node.js llhttp parser'
31 Jul 2026
b'Tucows (VDP)'
disclosed a bug submitted by
b'axolot23'
b'Stored XSS in nameserver field on account settings page'
31 Jul 2026
b'phpBB'
disclosed a bug submitted by
b'a7mmr'
b'Stored XSS via SVG Upload check_content() Blocklist Bypass & 256-Byte Scan Limit (Self-Propagating Worm)'
30 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'sinan-polat'
b'Permission Model bypass: process.report writes (and overwrites) files outside --allow-fs-write paths'
30 Jul 2026
b'Ruby on Rails'
disclosed a bug submitted by
b'friedchicken112211'
b'Active Storage Vips Transformer Missing validate_transformation CVE-2025-24293 Incomplete Fix'
30 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'vnyuh'
b'HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)'
30 Jul 2026
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b'GitHub scoped user to server tokens can escape their installation'
29 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'sy2n0'
b'Permission Model: --allow-fs-read/--allow-fs-write radix-tree prefix-boundary over-grant'
29 Jul 2026
b'HackerOne'
disclosed a bug submitted by
b'0v3rw4tch'
b'`exportReportPdf` mutation shows internal Activity'
29 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'yottt'
b'HTTPS Agent PFX object-array key collision allows mTLS client identity reuse across different per-request certificates'
29 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'0xoroot'
b'Permission Model Bypass: `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`'
29 Jul 2026
b'Rocket.Chat'
disclosed a bug submitted by
b'button142857'
b"Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)"
29 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'mistercloudsec'
b'Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh'
28 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'nick_frichette_dd'
b'Non-Production API Endpoints for the Amazon Cloudwatch Fails to Log to CloudTrail Resulting in Silent Permission Enumeration'
27 Jul 2026
b'Rocket.Chat'
disclosed a bug submitted by
b'0jayden'
b'Authentication Bypass via XML Signature Wrapping in SAML SSO'
27 Jul 2026
b'Monero'
disclosed a bug submitted by
b'redlobsterzzz'
b'ZMQ RPC Log Injection and Untrusted Payload Persistence'
24 Jul 2026
1
2
3
4
...
772
BY DENIS WERNER - @NOBBD -
IMPRESSUM