Stored XSS via SVG Upload β check_content() Blocklist Bypass & 256-Byte Scan Limit (Self-Propagating Worm)
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: phpBB
πΉ Reported By: a7mmr
πΉ State: π’ Resolved
πΉ Disclosed: July 30, 2026, 8:29pm (UTC)
π Source: HackerOne
A stored XSS vulnerability was discovered in phpBB 4.0.0-a2-dev. The vulnerability was caused by an incomplete blocklist for file uploads and a 256-byte read limit in the content scanning check. Specifically, SVG files with malicious payloads in the onload and onbegin attributes were able to bypass the content check and be stored on the server. Additionally, any content beyond the 256-byte limit was not scannedβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: phpBB
πΉ Reported By: a7mmr
πΉ State: π’ Resolved
πΉ Disclosed: July 30, 2026, 8:29pm (UTC)
π Source: HackerOne
A stored XSS vulnerability was discovered in phpBB 4.0.0-a2-dev. The vulnerability was caused by an incomplete blocklist for file uploads and a 256-byte read limit in the content scanning check. Specifically, SVG files with malicious payloads in the onload and onbegin attributes were able to bypass the content check and be stored on the server. Additionally, any content beyond the 256-byte limit was not scannedβ¦
π Read full report
Broken Link Hijacking (Impersonation) on jpl.nasa.gov via Unregistered Facebook URL
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Vansh_Rathore
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Vansh_Rathore
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2026
π Source: Bugcrowd
π Read full report
Access To ( nasa slack channel ) Vai Live Slack Invitation Link ( https://join.slack.com/t/nasa-ammos/shared_invite/zt-1mlgmk5c2-MgqVSyKzVRUWrXy87FNqPw )
πΉ Severity: High
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Kartiktantubai
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: High
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Kartiktantubai
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2026
π Source: Bugcrowd
π Read full report
Stored XSS in nameserver field on account settings page
πΉ Severity: Low
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Tucows (VDP)
πΉ Reported By: axolot23
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2026, 3:07pm (UTC)
π Source: HackerOne
A stored XSS vulnerability was discovered in the nameserver field on the account settings page. The lack of input validation and weak CSP configuration allowed the injection of malicious JavaScript code that executed when the settings page was reloaded. The vulnerability was limited to a self-XSS scenario, affecting only the account owner who injected the payload and not other users.
π Read full report
πΉ Severity: Low
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Tucows (VDP)
πΉ Reported By: axolot23
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2026, 3:07pm (UTC)
π Source: HackerOne
A stored XSS vulnerability was discovered in the nameserver field on the account settings page. The lack of input validation and weak CSP configuration allowed the injection of malicious JavaScript code that executed when the settings page was reloaded. The vulnerability was limited to a self-XSS scenario, affecting only the account owner who injected the payload and not other users.
π Read full report
HTTP Request Smuggling via Connection: close<TAB> in Node.js llhttp parser
πΉ Severity: Medium
πΉ Weakness: HTTP Request Smuggling
πΉ Reported To: Node.js
πΉ Reported By: nadav0077
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2026, 3:27pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Node.js HTTP server where it ignores the "Connection: close" header when the token is followed by a tab character. This allows an attacker to send a second request on the same connection, even after the first request should have closed the connection.
π Read full report
πΉ Severity: Medium
πΉ Weakness: HTTP Request Smuggling
πΉ Reported To: Node.js
πΉ Reported By: nadav0077
πΉ State: π’ Resolved
πΉ Disclosed: July 31, 2026, 3:27pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Node.js HTTP server where it ignores the "Connection: close" header when the token is followed by a tab character. This allows an attacker to send a second request on the same connection, even after the first request should have closed the connection.
π Read full report
π₯1
Data Integrity Risk & PII Exposure: Publicly Editable OPAG Collaboration Document (Google Sheets) via science.nasa.gov
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Vansh_Rathore
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 31, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Vansh_Rathore
πΉ State: βͺοΈ Informational
πΉ Disclosed: July 31, 2026
π Source: Bugcrowd
π Read full report
Unauthenticated team "income/payments" export ignores donor privacy settings (hide_giving, hide_from_lists) and uses frozen visibility, exposing donat
πΉ Severity: Medium | π° 100 USD
πΉ Reported To: Liberapay
πΉ Reported By: its9me
πΉ State: π’ Resolved
πΉ Disclosed: August 1, 2026, 12:27pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the unauthenticated team "income/payments" export feature of Liberapay. The vulnerability allowed an attacker to retrieve donor identity, exact donation amount, and donation dates for public donors, bypassing the donor's explicit privacy settings such as "hide_giving" and "hide_from_lists". The root cause was that the endpoint only honored the frozen visibility flag of the paymentβ¦
π Read full report
πΉ Severity: Medium | π° 100 USD
πΉ Reported To: Liberapay
πΉ Reported By: its9me
πΉ State: π’ Resolved
πΉ Disclosed: August 1, 2026, 12:27pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the unauthenticated team "income/payments" export feature of Liberapay. The vulnerability allowed an attacker to retrieve donor identity, exact donation amount, and donation dates for public donors, bypassing the donor's explicit privacy settings such as "hide_giving" and "hide_from_lists". The root cause was that the endpoint only honored the frozen visibility flag of the paymentβ¦
π Read full report
SMTP CRLF injection in custom SMTP recipient operand allows additional SMTP commands after authentication
πΉ Severity: Medium
πΉ Weakness: CRLF Injection
πΉ Reported To: curl
πΉ Reported By: dark_river
πΉ State: π΄ N/A
πΉ Disclosed: August 3, 2026, 7:16am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: CRLF Injection
πΉ Reported To: curl
πΉ Reported By: dark_river
πΉ State: π΄ N/A
πΉ Disclosed: August 3, 2026, 7:16am (UTC)
π Source: HackerOne
π Read full report
Unauthenticated Path Traversal (LFI) via /custom-sounds/ when CustomSounds uses FileSystem storage
πΉ Severity: High
πΉ Weakness: Path Traversal
πΉ Reported To: Rocket.Chat
πΉ Reported By: howtoplay
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2026, 1:35pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: High
πΉ Weakness: Path Traversal
πΉ Reported To: Rocket.Chat
πΉ Reported By: howtoplay
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2026, 1:35pm (UTC)
π Source: HackerOne
π Read full report
GitHub Retired UsernameTakeover From [aws/ββββββββ]
πΉ Severity: Low
πΉ Weakness: Inclusion of Functionality from Untrusted Control Sphere
πΉ Reported To: AWS VDP
πΉ Reported By: sh3d0w
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2026, 6:17pm (UTC)
π Source: HackerOne
A retired GitHub username was discovered to be unclaimed, allowing an attacker to register the username and create a repository with the same name as the original. As a result, the original link to the repository now points to the attacker-controlled repository, enabling a persistent repository hijack.
π Read full report
πΉ Severity: Low
πΉ Weakness: Inclusion of Functionality from Untrusted Control Sphere
πΉ Reported To: AWS VDP
πΉ Reported By: sh3d0w
πΉ State: π’ Resolved
πΉ Disclosed: August 3, 2026, 6:17pm (UTC)
π Source: HackerOne
A retired GitHub username was discovered to be unclaimed, allowing an attacker to register the username and create a repository with the same name as the original. As a result, the original link to the repository now points to the attacker-controlled repository, enabling a persistent repository hijack.
π Read full report
Heap use-after-free (write) in mev_forget_socket() via reentrant curl_easy_pause() β incomplete fix for CVE-2026-9080
πΉ Severity: Medium
πΉ Weakness: Use After Free
πΉ Reported To: curl
πΉ Reported By: juthawong
πΉ State: π΄ N/A
πΉ Disclosed: August 4, 2026, 2:55pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Use After Free
πΉ Reported To: curl
πΉ Reported By: juthawong
πΉ State: π΄ N/A
πΉ Disclosed: August 4, 2026, 2:55pm (UTC)
π Source: HackerOne
π Read full report
`relay_tx` wallet-rpc skips `--restricted-rpc` guard and lets any caller corrupt wallet state via attacker-controlled `pending_tx`
πΉ Severity: Critical
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Monero
πΉ Reported By: benisprlh
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 5:05am (UTC)
π Source: HackerOne
The `relay_tx` wallet-RPC method in Monero was found to bypass the `--restricted-rpc` guard, allowing any caller to corrupt the wallet state by submitting a malicious `pending_tx` blob. The issue was that the `on_relay_tx` handler did not perform any ownership checks on the supplied `pending_tx` before passing it to `commit_tx`, which then updated the wallet state based on the attacker-controlled data. Thisβ¦
π Read full report
πΉ Severity: Critical
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Monero
πΉ Reported By: benisprlh
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 5:05am (UTC)
π Source: HackerOne
The `relay_tx` wallet-RPC method in Monero was found to bypass the `--restricted-rpc` guard, allowing any caller to corrupt the wallet state by submitting a malicious `pending_tx` blob. The issue was that the `on_relay_tx` handler did not perform any ownership checks on the supplied `pending_tx` before passing it to `commit_tx`, which then updated the wallet state based on the attacker-controlled data. Thisβ¦
π Read full report
wallet-rpc describe_transfer uses real_output_in_tx_index instead of real_output: cold-wallet pre-sign review shows wrong ring member
πΉ Severity: Medium
πΉ Weakness: Array Index Underflow
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
The wallet-rpc method "describe_transfer" was found to use the wrong index when retrieving information about the ring members for each input. Instead of using the "real_output" index, which represents the position of the real entry in the ring, it used the "real_output_in_tx_index", which represents the position of the output in the source transaction. This resulted in the pre-sign review displaying the wrongβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Array Index Underflow
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
The wallet-rpc method "describe_transfer" was found to use the wrong index when retrieving information about the ring members for each input. Instead of using the "real_output" index, which represents the position of the real entry in the ring, it used the "real_output_in_tx_index", which represents the position of the output in the source transaction. This resulted in the pre-sign review displaying the wrongβ¦
π Read full report
SpendProofV1 txid-substitution: get_spend_proof/check_spend_proof do not verify returned transaction hash
πΉ Severity: Medium
πΉ Weakness: Missing Required Cryptographic Step
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero project where the get_spend_proof and check_spend_proof functions do not verify the returned transaction hash against the requested transaction ID. This allows a malicious or compromised daemon to provide a valid serialized transaction body for a different transaction than the one requested, which can be used to create or verify a spend proof for that differentβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Missing Required Cryptographic Step
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero project where the get_spend_proof and check_spend_proof functions do not verify the returned transaction hash against the requested transaction ID. This allows a malicious or compromised daemon to provide a valid serialized transaction body for a different transaction than the one requested, which can be used to create or verify a spend proof for that differentβ¦
π Read full report
wallet-rpc crash via malformed /gettransactions response (empty txs β vector::front() in check_tx_key / check_tx_proof)
πΉ Severity: High
πΉ Weakness: NULL Pointer Dereference
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero wallet software that could cause the wallet-rpc process to crash when handling a malformed response from the daemon's /gettransactions endpoint. The vulnerability was due to the wallet software making assumptions about the response structure that were not always valid, leading to undefined behavior when attempting to access empty data structures. The crash occurred whenβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: NULL Pointer Dereference
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero wallet software that could cause the wallet-rpc process to crash when handling a malformed response from the daemon's /gettransactions endpoint. The vulnerability was due to the wallet software making assumptions about the response structure that were not always valid, leading to undefined behavior when attempting to access empty data structures. The crash occurred whenβ¦
π Read full report
`check_reserve_proof` sums RingCT ECDH amounts without checking the output commitment
πΉ Severity: Medium
πΉ Weakness: Missing Required Cryptographic Step
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
The `check_reserve_proof` function in the Monero codebase was found to sum RingCT ECDH amounts without checking the output commitment. The decoded amount was added to the total without verifying that it matched the commitment, which could allow a malicious prover to claim larger reserves than actually exist on-chain.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Missing Required Cryptographic Step
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
The `check_reserve_proof` function in the Monero codebase was found to sum RingCT ECDH amounts without checking the output commitment. The decoded amount was added to the total without verifying that it matched the commitment, which could allow a malicious prover to claim larger reserves than actually exist on-chain.
π Read full report
`check_reserve_proof` counts duplicate entries: one output can inflate `total`
πΉ Severity: Medium
πΉ Weakness: Business Logic Errors
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
A vulnerability was discovered in the `check_reserve_proof` function in the Monero wallet software. The vulnerability allowed duplicate entries in the reserve proof, which could artificially inflate the reported total reserve amount without affecting the verification of individual entries. The issue was in the verifier logic, where the accounting was done in a flat manner, adding the output amount for each rowβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Business Logic Errors
πΉ Reported To: Monero
πΉ Reported By: bebensap
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 10:23am (UTC)
π Source: HackerOne
A vulnerability was discovered in the `check_reserve_proof` function in the Monero wallet software. The vulnerability allowed duplicate entries in the reserve proof, which could artificially inflate the reported total reserve amount without affecting the verification of individual entries. The issue was in the verifier logic, where the accounting was done in a flat manner, adding the output amount for each rowβ¦
π Read full report
curl Missing Sec-WebSocket-Accept Verification Enables MITM WebSocket Session Hijacking
πΉ Severity: No Rating
πΉ Weakness: Man-in-the-Middle
πΉ Reported To: curl
πΉ Reported By: kiyin
πΉ State: π΄ N/A
πΉ Disclosed: August 5, 2026, 11:13am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Man-in-the-Middle
πΉ Reported To: curl
πΉ Reported By: kiyin
πΉ State: π΄ N/A
πΉ Disclosed: August 5, 2026, 11:13am (UTC)
π Source: HackerOne
π Read full report
Unauthenticated RCE in Taskcluster web-server via GraphQL filter argument (sift $where)
πΉ Severity: Critical | π° 12,000 USD
πΉ Weakness: Code Injection
πΉ Reported To: Mozilla
πΉ Reported By: griffinf
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 3:50pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Taskcluster web-server that allowed unauthenticated remote code execution through the GraphQL filter argument. The issue was caused by the use of the 'sift' library, which compiled the filter's '$where' string into a function using 'new Function' and executed it. This allowed an attacker to run arbitrary JavaScript in the context of the Node.js process, resulting in theβ¦
π Read full report
πΉ Severity: Critical | π° 12,000 USD
πΉ Weakness: Code Injection
πΉ Reported To: Mozilla
πΉ Reported By: griffinf
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 3:50pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Taskcluster web-server that allowed unauthenticated remote code execution through the GraphQL filter argument. The issue was caused by the use of the 'sift' library, which compiled the filter's '$where' string into a function using 'new Function' and executed it. This allowed an attacker to run arbitrary JavaScript in the context of the Node.js process, resulting in theβ¦
π Read full report
[Wii U/3DS/Switch] Improper bounds check in StationURL in all NEX clients leading to remote crash/RCE
πΉ Severity: Low
πΉ Weakness: Stack Overflow
πΉ Reported To: Nintendo
πΉ Reported By: jonbarrow
πΉ State: π΅ Duplicate
πΉ Disclosed: August 7, 2026, 1:04am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Weakness: Stack Overflow
πΉ Reported To: Nintendo
πΉ Reported By: jonbarrow
πΉ State: π΅ Duplicate
πΉ Disclosed: August 7, 2026, 1:04am (UTC)
π Source: HackerOne
π Read full report
URL API: triple-slash parses path segment as hostname
πΉ Severity: Medium
πΉ Weakness: Use of Incorrectly-Resolved Name or Reference
πΉ Reported To: curl
πΉ Reported By: thinhlx
πΉ State: π΄ N/A
πΉ Disclosed: August 7, 2026, 8:49pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Use of Incorrectly-Resolved Name or Reference
πΉ Reported To: curl
πΉ Reported By: thinhlx
πΉ State: π΄ N/A
πΉ Disclosed: August 7, 2026, 8:49pm (UTC)
π Source: HackerOne
π Read full report