Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections
πΉ Severity: Medium
πΉ Weakness: Incorrect Permission Assignment for Critical Resource
πΉ Reported To: AWS VDP
πΉ Reported By: mistercloudsec
πΉ State: π’ Resolved
πΉ Disclosed: July 15, 2026, 3:12pm (UTC)
π Source: HackerOne
The Bedrock AgentCore Starter Toolkit was found to create IAM roles for the AgentCore Gateway with trust policies that lacked certain condition keys. This enabled a cross-account confused deputy attack where any AgentCore workload in any AWS account could assume the victim's Gateway role. The role granted access to sensitive resources in the account, including secrets, KMS, Lambda, DynamoDB, and S3.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Incorrect Permission Assignment for Critical Resource
πΉ Reported To: AWS VDP
πΉ Reported By: mistercloudsec
πΉ State: π’ Resolved
πΉ Disclosed: July 15, 2026, 3:12pm (UTC)
π Source: HackerOne
The Bedrock AgentCore Starter Toolkit was found to create IAM roles for the AgentCore Gateway with trust policies that lacked certain condition keys. This enabled a cross-account confused deputy attack where any AgentCore workload in any AWS account could assume the victim's Gateway role. The role granted access to sensitive resources in the account, including secrets, KMS, Lambda, DynamoDB, and S3.
π Read full report
Able to bypass authorization logic and gain more access then intended
πΉ Severity: Medium
πΉ Reported To: GitHub
πΉ Reported By: vaib25vicky
πΉ State: π’ Resolved
πΉ Disclosed: July 15, 2026, 4:35pm (UTC)
π Source: HackerOne
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. The vulnerability was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
π Read full report
πΉ Severity: Medium
πΉ Reported To: GitHub
πΉ Reported By: vaib25vicky
πΉ State: π’ Resolved
πΉ Disclosed: July 15, 2026, 4:35pm (UTC)
π Source: HackerOne
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. The vulnerability was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
π Read full report
Stored XSS in Rocket.Chat HTML File Export β Unauthenticated Entry via LiveChat
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Rocket.Chat
πΉ Reported By: olidayw
πΉ State: π’ Resolved
πΉ Disclosed: July 16, 2026, 5:02am (UTC)
π Source: HackerOne
A vulnerability was discovered in the HTML file export feature of Rocket.Chat. The vulnerability allowed an attacker to inject arbitrary JavaScript code that would execute when the exported HTML file was opened. The root cause was that the application did not properly sanitize or escape user-supplied data before including it in the exported HTML. As a result, an unauthenticated attacker could leverage theβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Rocket.Chat
πΉ Reported By: olidayw
πΉ State: π’ Resolved
πΉ Disclosed: July 16, 2026, 5:02am (UTC)
π Source: HackerOne
A vulnerability was discovered in the HTML file export feature of Rocket.Chat. The vulnerability allowed an attacker to inject arbitrary JavaScript code that would execute when the exported HTML file was opened. The root cause was that the application did not properly sanitize or escape user-supplied data before including it in the exported HTML. As a result, an unauthenticated attacker could leverage theβ¦
π Read full report
π₯1
πΈ Top 10 biggest bounties ever paid on HackerOne
Publicly disclosed. Real payouts. One bug each π
π₯ $50,000 β Shopify
GitHub access token exposure Β· augustozanellato
π₯ $39,999 β Uber
API access Β· tomnomnom
π₯ $35,000 β GitLab
Account takeover via password reset Β· asterion04
4οΈβ£ $33,510 β GitLab
RCE via GitHub import Β· vakzz
5οΈβ£ $30,000 β PayPal
Dependency confusion RCE Β· alexbirsan
6οΈβ£ $29,000 β GitLab
Arbitrary file read Β· vakzz
7οΈβ£ $25,000 β Valve
SQL injection in report_xml.php Β· moskowsky
8οΈβ£ $25,000 β Snapchat
Exposed Kubernetes API β RCE Β· txt3rob
9οΈβ£ $25,000 β HackerOne
Disclosing a private program Β· haxta4ok00
π $20,160 β X / xAI
Pre-auth RCE Β· orange
π‘ And these are just the public ones β the biggest private bounties go way higher.
Which one surprises you most? π€―
Publicly disclosed. Real payouts. One bug each π
π₯ $50,000 β Shopify
GitHub access token exposure Β· augustozanellato
π₯ $39,999 β Uber
API access Β· tomnomnom
π₯ $35,000 β GitLab
Account takeover via password reset Β· asterion04
4οΈβ£ $33,510 β GitLab
RCE via GitHub import Β· vakzz
5οΈβ£ $30,000 β PayPal
Dependency confusion RCE Β· alexbirsan
6οΈβ£ $29,000 β GitLab
Arbitrary file read Β· vakzz
7οΈβ£ $25,000 β Valve
SQL injection in report_xml.php Β· moskowsky
8οΈβ£ $25,000 β Snapchat
Exposed Kubernetes API β RCE Β· txt3rob
9οΈβ£ $25,000 β HackerOne
Disclosing a private program Β· haxta4ok00
π $20,160 β X / xAI
Pre-auth RCE Β· orange
π‘ And these are just the public ones β the biggest private bounties go way higher.
Which one surprises you most? π€―
π₯1
Bugpoint pinned Β«πΈ Top 10 biggest bounties ever paid on HackerOne Publicly disclosed. Real payouts. One bug each π π₯ $50,000 β Shopify GitHub access token exposure Β· augustozanellato π₯ $39,999 β Uber API access Β· tomnomnom π₯ $35,000 β GitLab Account takeover via passwordβ¦Β»
Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes
πΉ Severity: Low
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Monero
πΉ Reported By: int0ha_
πΉ State: π’ Resolved
πΉ Disclosed: July 20, 2026, 12:15am (UTC)
π Source: HackerOne
The `/get_alt_blocks_hashes` RPC endpoint was restricted to prevent unintended access to alternative block hashes. The endpoint had previously been unrestricted.
π Read full report
πΉ Severity: Low
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Monero
πΉ Reported By: int0ha_
πΉ State: π’ Resolved
πΉ Disclosed: July 20, 2026, 12:15am (UTC)
π Source: HackerOne
The `/get_alt_blocks_hashes` RPC endpoint was restricted to prevent unintended access to alternative block hashes. The endpoint had previously been unrestricted.
π Read full report
β€1
Blind Enumeration of Private Card Names via Sort Oracle and ID Discovery
πΉ Severity: Low
πΉ Reported To: Trello
πΉ Reported By: BobAshEf
πΉ State: π’ Resolved
πΉ Disclosed: July 20, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: Trello
πΉ Reported By: BobAshEf
πΉ State: π’ Resolved
πΉ Disclosed: July 20, 2026
π Source: Bugcrowd
π Read full report
Public Google Maps API key on www.globe.gov allows Geocoding API calls (billable use)
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: madhu873
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 21, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: madhu873
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 21, 2026
π Source: Bugcrowd
π Read full report
OAuth redirect uri validation bypass for :proxima_first_party_sync apps
πΉ Severity: High
πΉ Weakness: Open Redirect
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: July 21, 2026, 9:43pm (UTC)
π Source: HackerOne
A vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. The vulnerability was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. The vulnerability was reported through the GitHub Bug Bounty program.
π Read full report
πΉ Severity: High
πΉ Weakness: Open Redirect
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: July 21, 2026, 9:43pm (UTC)
π Source: HackerOne
A vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. The vulnerability was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. The vulnerability was reported through the GitHub Bug Bounty program.
π Read full report
connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability
πΉ Severity: High | π° 1,337 USD
πΉ Weakness: Improper Verification of Cryptographic Signature
πΉ Reported To: 8x8
πΉ Reported By: kyotozzx
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 4:15am (UTC)
π Source: HackerOne
A JWT algorithm confusion vulnerability was reported in the `v1` API of `connect.8x8.com`. The JWT verifier did not enforce algorithm pinning and would accept HS256 tokens signed with the RSA public key used as an HMAC secret. The issue was remediated by enforcing RS256 algorithm pinning in the `v1` API verifier.
π Read full report
πΉ Severity: High | π° 1,337 USD
πΉ Weakness: Improper Verification of Cryptographic Signature
πΉ Reported To: 8x8
πΉ Reported By: kyotozzx
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 4:15am (UTC)
π Source: HackerOne
A JWT algorithm confusion vulnerability was reported in the `v1` API of `connect.8x8.com`. The JWT verifier did not enforce algorithm pinning and would accept HS256 tokens signed with the RSA public key used as an HMAC secret. The issue was remediated by enforcing RS256 algorithm pinning in the `v1` API verifier.
π Read full report
GitHub user to server tokens can create issues in any public repository
πΉ Severity: Medium
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 7:39pm (UTC)
π Source: HackerOne
A vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. The authorization check only verified that the installation had read permissions on the target repository rather than verifying that the token's installation was explicitly granted access toβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 7:39pm (UTC)
π Source: HackerOne
A vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. The authorization check only verified that the installation had read permissions on the target repository rather than verifying that the token's installation was explicitly granted access toβ¦
π Read full report
AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF
πΉ Severity: High
πΉ Weakness: Authentication Bypass
πΉ Reported To: AWS VDP
πΉ Reported By: notnotnotveg
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 7:53pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: High
πΉ Weakness: Authentication Bypass
πΉ Reported To: AWS VDP
πΉ Reported By: notnotnotveg
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 7:53pm (UTC)
π Source: HackerOne
π Read full report
Identity Theft via Broken Link Hijacking on NASA Astronaut News Release Page
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: muhammadabdillah64edc3
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: muhammadabdillah64edc3
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
Arbitrary External Redirect Through SAML RelayState After Successful Authentication
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: 2yuk
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: 2yuk
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
Blind SQL Injection in Search Functionality Leads to Full Database Extraction
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: molany
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: molany
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
Exposed Credentials in Public .env File on NASA Git Repository
πΉ Severity: Medium
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Hunt3rboy
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Medium
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Hunt3rboy
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
Critical Authentication Bypass via Path Normalization (Double Slash) on Live NASA MODAPS OKAPI Production Instance
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: marcelojr
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: marcelojr
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
RE : Host Header Injection leads to Cookie Domain Manipulation on sealevel.nasa.gov
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: sanjay910
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: sanjay910
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
Reflected XSS and HTML Injection on cce-signin.gsfc.nasa.gov via 'popup_flag' parameter
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ItsS4LEH
πΉ State: π’ Resolved
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ItsS4LEH
πΉ State: π’ Resolved
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
Data-Sculptor CSV expression evaluation leads to backend RCE, Kubernetes serviceaccount token disclosure, and authenticated Kubernetes control-plane access
πΉ Severity: High
πΉ Reported To: Atlassian
πΉ Reported By: MononcleMich
πΉ State: π’ Resolved
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: High
πΉ Reported To: Atlassian
πΉ Reported By: MononcleMich
πΉ State: π’ Resolved
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
ZMQ RPC Log Injection and Untrusted Payload Persistence
πΉ Severity: Medium
πΉ Weakness: CRLF Injection
πΉ Reported To: Monero
πΉ Reported By: redlobsterzzz
πΉ State: π’ Resolved
πΉ Disclosed: July 24, 2026, 7:19pm (UTC)
π Source: HackerOne
A vulnerability was reported in the Monero CLI daemon where the ZMQ RPC request path logs untrusted request content before semantic validation. This allowed a remote party with access to the ZMQ endpoint to inject newline and control-character content into daemon logs, enabling log forging. The vulnerability was introduced in commit 77986023c3 and affected releases from v0.12.0.0 through v0.18.4.6, as well as theβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: CRLF Injection
πΉ Reported To: Monero
πΉ Reported By: redlobsterzzz
πΉ State: π’ Resolved
πΉ Disclosed: July 24, 2026, 7:19pm (UTC)
π Source: HackerOne
A vulnerability was reported in the Monero CLI daemon where the ZMQ RPC request path logs untrusted request content before semantic validation. This allowed a remote party with access to the ZMQ endpoint to inject newline and control-character content into daemon logs, enabling log forging. The vulnerability was introduced in commit 77986023c3 and affected releases from v0.12.0.0 through v0.18.4.6, as well as theβ¦
π Read full report