REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'CVE-2026-9547: SSH improper host validation'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'fafawf'
b'CVE-2026-9546: sending old referer'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'keen4n'
b'CVE-2026-9079: stale proxy password leak'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'CVE-2026-9080: UAF after pause in socket callback'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'bagder'
b'CVE-2026-8286: wrong STARTTLS connection reuse'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'CVE-2026-8932: incomplete mTLS config matching in conn reuse'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'adyej'
b'CVE-2026-8927: env-set cross-proxy Digest auth state leak'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'CVE-2026-8925: SASL double-free'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'giant_anteater'
b'CVE-2026-8926: password leak with netrc and user in URL'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'areksaxyz'
b'CVE-2026-8458: wrong reuse for different services'
24 Jun 2026
b'SingleStore'
disclosed a bug submitted by
b'axolot23'
b'Insufficient checks in the file path parameter allow writing to unauthorized directories'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'hahahkim'
b'CVE-2026-9545: exposing HTTP/3 early data'
24 Jun 2026
b'curl'
disclosed a bug submitted by
b'jjchuck'
b'CVE-2026-11856: cross-origin Digest auth state leak'
24 Jun 2026
b'Mozilla'
disclosed a bug submitted by
b'anshuman_bh'
b'Taskcluster web-server OAuth2 authorization codes are reusable and the exchange handler checks the wrong expiry column'
23 Jun 2026
b'Node.js'
disclosed a bug submitted by
b'yottt'
b'Node --run POSIX positional argument escaping allows shell command injection'
23 Jun 2026
b'Khan Academy'
disclosed a bug submitted by
b'farr'
b'1-Click Account Takeover via Open Redirect through Regex Bypass in Domain Validation'
20 Jun 2026
b'Node.js'
disclosed a bug submitted by
b'pimterry'
b'HTTP/2 sessions never clean up after GOAWAY on invalid protocol errors'
18 Jun 2026
b'Node.js'
disclosed a bug submitted by
b'suul'
b'Permission Model Bypass via `process.report.writeReport()` Path Misvalidation'
18 Jun 2026
b'Shopify'
disclosed a bug submitted by
b'saltymermaid'
b'Reflected XSS in AI Chat Bot Greetings at help.shopify.com via Markdown Image Rendering'
18 Jun 2026
b'HackerOne'
disclosed a bug submitted by
b'brumbelow'
b'Authenticated Elasticsearch Painless script execution via Query.search.sort_query on hackerone.com/graphql'
17 Jun 2026
1
2
3
4
5
6
...
770
BY DENIS WERNER - @NOBBD -
IMPRESSUM