REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'SingleStore'
disclosed a bug submitted by
b'bl4ck-'
b'Privilege Escalation Access to the Alert Subscribers page for users with low privileges'
01 Jul 2026
b'Node.js'
disclosed a bug submitted by
b'saif-01'
b'Improper Input Validation HTTP Response Parser Unconditionally Accepts Bare CR in Status Line'
01 Jul 2026
b'curl'
disclosed a bug submitted by
b'carehi1324'
b'heap-use-after-free in curl_easy_cleanup() called from callback'
30 Jun 2026
b'curl'
disclosed a bug submitted by
b'a6b30108'
b'setopt(VERIFYPEER) from callback bypasses TLS verify on connection reuse'
30 Jun 2026
b'curl'
disclosed a bug submitted by
b'bigtang'
b'ssh_config_matches is dead code: unauthorized SSH key reuse'
30 Jun 2026
b'curl'
disclosed a bug submitted by
b'smaeljaish771'
b'CURLSHOPT_UNSHARE race can cause UAF in shared SSL session cache during HTTPS transfer'
30 Jun 2026
b'curl'
disclosed a bug submitted by
b'th3hound'
b'libcurl upload read callbacks miss recursive API guard, allowing prohibited multi API reentry and ASAN-confirmed UAF'
30 Jun 2026
b'Discourse'
disclosed a bug submitted by
b'dpaysm'
b'Denial of Service (DoS) Vulnerability in Drafts Creation Endpoint'
30 Jun 2026
b'Monero'
disclosed a bug submitted by
b'kklam32'
b'Inverted ternary in peerlist_manager::filter() allows unlimited whitelist entries per host via different ports'
29 Jun 2026
b'Monero'
disclosed a bug submitted by
b'xnbya'
b'Remote node DOS'
29 Jun 2026
b'curl'
disclosed a bug submitted by
b'homanp'
b'UAF read in mev_pollset_diff() trace path after curl_easy_pause() in socket callback'
28 Jun 2026
b'curl'
disclosed a bug submitted by
b'stze'
b'Use-after-free in `mev_forget_socket` when `curl_easy_pause()` is called from a `CURL_POLL_REMOVE` socket callback (incomplete fix of CVE-2026-9080)'
28 Jun 2026
b'curl'
disclosed a bug submitted by
b'b1gtang'
b'mbedTLS / wolfSSL / rustls backends silently skip hostname verification when CURLOPT_SSL_VERIFYPEER=0'
26 Jun 2026
b'curl'
disclosed a bug submitted by
b'tneelc'
b'CURLOPT_HAPROXY_CLIENT_IP lacks input validation, enabling HAProxy PROXY protocol injection'
26 Jun 2026
b'Revive Adserver'
disclosed a bug submitted by
b'doomtech'
b'PHP code injection in delivery-limitation `logical` validation bypass - XML-RPC setChannelTargeting'
25 Jun 2026
b'Revive Adserver'
disclosed a bug submitted by
b'garuthacktvist'
b'XMLRPC login leak exposes valid session ID enabling unauthorized API access'
25 Jun 2026
b'Revive Adserver'
disclosed a bug submitted by
b'kanon4'
b'Reflected XSS via unsanitised refresh parameter in zone invocation tag'
25 Jun 2026
b'Revive Adserver'
disclosed a bug submitted by
b'riodrwn'
b'PHP code injection in delivery-limitation `logical` validation bypass'
25 Jun 2026
b'Revive Adserver'
disclosed a bug submitted by
b'an_gr_y'
b'Stored XSS in maintenance tools via unescaped entity names'
25 Jun 2026
b'Revive Adserver'
disclosed a bug submitted by
b'an_gr_y'
b'CSRF in zoneinclude.php allows unauthorized banner and campaign linking'
25 Jun 2026
1
2
3
4
5
6
...
772
BY DENIS WERNER - @NOBBD -
IMPRESSUM