GitHub user to server tokens can create issues in any public repository
πΉ Severity: Medium
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 7:39pm (UTC)
π Source: HackerOne
A vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. The authorization check only verified that the installation had read permissions on the target repository rather than verifying that the token's installation was explicitly granted access toβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 7:39pm (UTC)
π Source: HackerOne
A vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. The authorization check only verified that the installation had read permissions on the target repository rather than verifying that the token's installation was explicitly granted access toβ¦
π Read full report
AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF
πΉ Severity: High
πΉ Weakness: Authentication Bypass
πΉ Reported To: AWS VDP
πΉ Reported By: notnotnotveg
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 7:53pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: High
πΉ Weakness: Authentication Bypass
πΉ Reported To: AWS VDP
πΉ Reported By: notnotnotveg
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026, 7:53pm (UTC)
π Source: HackerOne
π Read full report
Identity Theft via Broken Link Hijacking on NASA Astronaut News Release Page
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: muhammadabdillah64edc3
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: muhammadabdillah64edc3
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
Arbitrary External Redirect Through SAML RelayState After Successful Authentication
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: 2yuk
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: 2yuk
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
Blind SQL Injection in Search Functionality Leads to Full Database Extraction
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: molany
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: molany
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
Exposed Credentials in Public .env File on NASA Git Repository
πΉ Severity: Medium
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Hunt3rboy
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Medium
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Hunt3rboy
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
Critical Authentication Bypass via Path Normalization (Double Slash) on Live NASA MODAPS OKAPI Production Instance
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: marcelojr
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: marcelojr
πΉ State: π’ Resolved
πΉ Disclosed: July 22, 2026
π Source: Bugcrowd
π Read full report
RE : Host Header Injection leads to Cookie Domain Manipulation on sealevel.nasa.gov
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: sanjay910
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: sanjay910
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
Reflected XSS and HTML Injection on cce-signin.gsfc.nasa.gov via 'popup_flag' parameter
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ItsS4LEH
πΉ State: π’ Resolved
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ItsS4LEH
πΉ State: π’ Resolved
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
Data-Sculptor CSV expression evaluation leads to backend RCE, Kubernetes serviceaccount token disclosure, and authenticated Kubernetes control-plane access
πΉ Severity: High
πΉ Reported To: Atlassian
πΉ Reported By: MononcleMich
πΉ State: π’ Resolved
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: High
πΉ Reported To: Atlassian
πΉ Reported By: MononcleMich
πΉ State: π’ Resolved
πΉ Disclosed: July 23, 2026
π Source: Bugcrowd
π Read full report
ZMQ RPC Log Injection and Untrusted Payload Persistence
πΉ Severity: Medium
πΉ Weakness: CRLF Injection
πΉ Reported To: Monero
πΉ Reported By: redlobsterzzz
πΉ State: π’ Resolved
πΉ Disclosed: July 24, 2026, 7:19pm (UTC)
π Source: HackerOne
A vulnerability was reported in the Monero CLI daemon where the ZMQ RPC request path logs untrusted request content before semantic validation. This allowed a remote party with access to the ZMQ endpoint to inject newline and control-character content into daemon logs, enabling log forging. The vulnerability was introduced in commit 77986023c3 and affected releases from v0.12.0.0 through v0.18.4.6, as well as theβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: CRLF Injection
πΉ Reported To: Monero
πΉ Reported By: redlobsterzzz
πΉ State: π’ Resolved
πΉ Disclosed: July 24, 2026, 7:19pm (UTC)
π Source: HackerOne
A vulnerability was reported in the Monero CLI daemon where the ZMQ RPC request path logs untrusted request content before semantic validation. This allowed a remote party with access to the ZMQ endpoint to inject newline and control-character content into daemon logs, enabling log forging. The vulnerability was introduced in commit 77986023c3 and affected releases from v0.12.0.0 through v0.18.4.6, as well as theβ¦
π Read full report
Authentication Bypass via XML Signature Wrapping in SAML SSO
πΉ Severity: Critical
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Rocket.Chat
πΉ Reported By: 0jayden
πΉ State: π’ Resolved
πΉ Disclosed: July 27, 2026, 4:37pm (UTC)
π Source: HackerOne
The SAML SSO implementation in Rocket.Chat verified XML signatures but did not bind the validated signature to the `samlp:Response` or `saml:Assertion`. As a result, an attacker could submit a wrapped document carrying forged identity attributes alongside a valid signature made by the trusted IdP certificate, and gain unauthorized access to the system.
π Read full report
πΉ Severity: Critical
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Rocket.Chat
πΉ Reported By: 0jayden
πΉ State: π’ Resolved
πΉ Disclosed: July 27, 2026, 4:37pm (UTC)
π Source: HackerOne
The SAML SSO implementation in Rocket.Chat verified XML signatures but did not bind the validated signature to the `samlp:Response` or `saml:Assertion`. As a result, an attacker could submit a wrapped document carrying forged identity attributes alongside a valid signature made by the trusted IdP certificate, and gain unauthorized access to the system.
π Read full report
Non-Production API Endpoints for the Amazon Cloudwatch Fails to Log to CloudTrail Resulting in Silent Permission Enumeration
πΉ Severity: Medium
πΉ Weakness: Insufficient Logging
πΉ Reported To: AWS VDP
πΉ Reported By: nick_frichette_dd
πΉ State: π’ Resolved
πΉ Disclosed: July 27, 2026, 7:51pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Amazon CloudWatch service, where certain non-production API endpoints could be used to perform permission enumeration without generating corresponding CloudTrail events. This allowed for silent testing of compromised IAM credentials. The vulnerability was reported to AWS, which acknowledged it as a security issue. Specific endpoints and operations that exhibited this behaviorβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Insufficient Logging
πΉ Reported To: AWS VDP
πΉ Reported By: nick_frichette_dd
πΉ State: π’ Resolved
πΉ Disclosed: July 27, 2026, 7:51pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Amazon CloudWatch service, where certain non-production API endpoints could be used to perform permission enumeration without generating corresponding CloudTrail events. This allowed for silent testing of compromised IAM credentials. The vulnerability was reported to AWS, which acknowledged it as a security issue. Specific endpoints and operations that exhibited this behaviorβ¦
π Read full report
Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh
πΉ Severity: Medium
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: AWS VDP
πΉ Reported By: mistercloudsec
πΉ State: π’ Resolved
πΉ Disclosed: July 28, 2026, 3:29pm (UTC)
π Source: HackerOne
A vulnerability was found in the Bedrock AgentCore Code Interpreter sandbox. The sandbox granted a user passwordless sudo access to a script that deployed certificates to the OS trust store. An attacker could have generated a rogue CA certificate, placed it in a writable directory, and then used the sudo-allowed script to inject the rogue CA into the trust store. This could have been used to performβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: AWS VDP
πΉ Reported By: mistercloudsec
πΉ State: π’ Resolved
πΉ Disclosed: July 28, 2026, 3:29pm (UTC)
π Source: HackerOne
A vulnerability was found in the Bedrock AgentCore Code Interpreter sandbox. The sandbox granted a user passwordless sudo access to a script that deployed certificates to the OS trust store. An attacker could have generated a rogue CA certificate, placed it in a writable directory, and then used the sudo-allowed script to inject the rogue CA into the trust store. This could have been used to performβ¦
π Read full report
Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)
πΉ Severity: High
πΉ Weakness: Server-Side Request Forgery (SSRF)
πΉ Reported To: Rocket.Chat
πΉ Reported By: button142857
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 1:48am (UTC)
π Source: HackerOne
An SSRF vulnerability was discovered in Rocket.Chat version 7.13.2 that was caused by a DNS rebinding attack. The vulnerability allowed an attacker to bypass a security check and access internal hosts on the same network as the Rocket.Chat server. The vulnerability was present in the SMS integration feature that used the `checkUrlForSsrf` function, which was bypassed by the DNS rebinding attack.
π Read full report
πΉ Severity: High
πΉ Weakness: Server-Side Request Forgery (SSRF)
πΉ Reported To: Rocket.Chat
πΉ Reported By: button142857
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 1:48am (UTC)
π Source: HackerOne
An SSRF vulnerability was discovered in Rocket.Chat version 7.13.2 that was caused by a DNS rebinding attack. The vulnerability allowed an attacker to bypass a security check and access internal hosts on the same network as the Rocket.Chat server. The vulnerability was present in the SMS integration feature that used the `checkUrlForSsrf` function, which was bypassed by the DNS rebinding attack.
π Read full report
Permission Model Bypass: `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`
πΉ Severity: Low
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Node.js
πΉ Reported By: 0xoroot
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 2:16pm (UTC)
π Source: HackerOne
A flaw in Node.js Permission Model enforcement was discovered that allowed `trace_events.createTracing().enable()` to write trace logs outside of the `--allow-fs-write` setting. This vulnerability affected Node.js versions 22.x, 24.x, and 26.x.
π Read full report
πΉ Severity: Low
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Node.js
πΉ Reported By: 0xoroot
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 2:16pm (UTC)
π Source: HackerOne
A flaw in Node.js Permission Model enforcement was discovered that allowed `trace_events.createTracing().enable()` to write trace logs outside of the `--allow-fs-write` setting. This vulnerability affected Node.js versions 22.x, 24.x, and 26.x.
π Read full report
HTTPS Agent PFX object-array key collision allows mTLS client identity reuse across different per-request certificates
πΉ Severity: Medium
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Node.js
πΉ Reported By: yottt
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 2:45pm (UTC)
π Source: HackerOne
A flaw in Node.js HTTPS Agent connection reuse was discovered that could cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affected Node.js versions 26.x, 24.x, and 22.x.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Node.js
πΉ Reported By: yottt
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 2:45pm (UTC)
π Source: HackerOne
A flaw in Node.js HTTPS Agent connection reuse was discovered that could cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affected Node.js versions 26.x, 24.x, and 22.x.
π Read full report
`exportReportPdf` mutation shows internal Activity
πΉ Severity: High
πΉ Reported To: HackerOne
πΉ Reported By: 0v3rw4tch
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 3:01pm (UTC)
π Source: HackerOne
A vulnerability was identified in the PDF export path for disclosed reports. When a report was exported to PDF, the export pipeline did not apply the same visibility and authorization scoping that governs the normal report view. The root cause was that PDF generation assembled report content from the underlying timeline without re-checking each activity against the requester's permission level. The issue wasβ¦
π Read full report
πΉ Severity: High
πΉ Reported To: HackerOne
πΉ Reported By: 0v3rw4tch
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 3:01pm (UTC)
π Source: HackerOne
A vulnerability was identified in the PDF export path for disclosed reports. When a report was exported to PDF, the export pipeline did not apply the same visibility and authorization scoping that governs the normal report view. The root cause was that PDF generation assembled report content from the underlying timeline without re-checking each activity against the requester's permission level. The issue wasβ¦
π Read full report
Permission Model: --allow-fs-read/--allow-fs-write radix-tree prefix-boundary over-grant
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Node.js
πΉ Reported By: sy2n0
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 11:00pm (UTC)
π Source: HackerOne
A flaw was discovered in the Node.js Permission Model's enforcement of filesystem access control. The vulnerability could allow an attacker granted access to one path to read from or write to paths outside the intended filesystem allowlist, due to issues with the radix-tree prefix-boundary handling. This affected Node.js versions in the main, 22.x, 24.x, and 26.x branches.
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Node.js
πΉ Reported By: sy2n0
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 11:00pm (UTC)
π Source: HackerOne
A flaw was discovered in the Node.js Permission Model's enforcement of filesystem access control. The vulnerability could allow an attacker granted access to one path to read from or write to paths outside the intended filesystem allowlist, due to issues with the radix-tree prefix-boundary handling. This affected Node.js versions in the main, 22.x, 24.x, and 26.x branches.
π Read full report
GitHub scoped user to server tokens can escape their installation
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 11:35pm (UTC)
π Source: HackerOne
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server was discovered. The vulnerability allowed an authenticated attacker to access private repositories outside the intended installation scope, which could have included write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context. Thisβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: July 29, 2026, 11:35pm (UTC)
π Source: HackerOne
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server was discovered. The vulnerability allowed an authenticated attacker to access private repositories outside the intended installation scope, which could have included write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context. Thisβ¦
π Read full report
HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)
πΉ Severity: Medium
πΉ Weakness: Exploiting Incorrectly Configured SSL/TLS
πΉ Reported To: Node.js
πΉ Reported By: vnyuh
πΉ State: π’ Resolved
πΉ Disclosed: July 30, 2026, 2:09am (UTC)
π Source: HackerOne
A vulnerability was identified in Node.js where HTTPS Agent TLS session reuse skipped hostname verification across identity policies, which was an incomplete fix for CVE-2026-48934. This affected Node.js versions 22.x, 24.x, and 26.x.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Exploiting Incorrectly Configured SSL/TLS
πΉ Reported To: Node.js
πΉ Reported By: vnyuh
πΉ State: π’ Resolved
πΉ Disclosed: July 30, 2026, 2:09am (UTC)
π Source: HackerOne
A vulnerability was identified in Node.js where HTTPS Agent TLS session reuse skipped hostname verification across identity policies, which was an incomplete fix for CVE-2026-48934. This affected Node.js versions 22.x, 24.x, and 26.x.
π Read full report