Windows SSPI connection-pool probe can reuse a connection under the wrong user
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Spoofing
πΉ Reported To: curl
πΉ Reported By: mr4bugs
πΉ State: π΄ N/A
πΉ Disclosed: August 14, 2026, 12:05pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Spoofing
πΉ Reported To: curl
πΉ Reported By: mr4bugs
πΉ State: π΄ N/A
πΉ Disclosed: August 14, 2026, 12:05pm (UTC)
π Source: HackerOne
π Read full report
TaskProcessing callback authorization bypass allows ex-members to post as Assistant Talk Bot
πΉ Severity: Medium
πΉ Weakness: Insecure Direct Object Reference (IDOR)
πΉ Reported To: Nextcloud
πΉ Reported By: kuninogu
πΉ State: π’ Resolved
πΉ Disclosed: August 14, 2026, 2:50pm (UTC)
π Source: HackerOne
A vulnerability was discovered that allowed an authenticated low-privilege user to cause the trusted Assistant Talk Bot to post attacker-guided AI-generated content into a Talk conversation, even after the user had left the conversation. The issue was caused by the Talk Bot's endpoint trusting the caller-supplied conversation token without verifying that the callback belonged to a task originally scheduled by theβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Insecure Direct Object Reference (IDOR)
πΉ Reported To: Nextcloud
πΉ Reported By: kuninogu
πΉ State: π’ Resolved
πΉ Disclosed: August 14, 2026, 2:50pm (UTC)
π Source: HackerOne
A vulnerability was discovered that allowed an authenticated low-privilege user to cause the trusted Assistant Talk Bot to post attacker-guided AI-generated content into a Talk conversation, even after the user had left the conversation. The issue was caused by the Talk Bot's endpoint trusting the caller-supplied conversation token without verifying that the callback belonged to a task originally scheduled by theβ¦
π Read full report
`set_daemon` wallet-rpc silently ignores `ssl_allowed_fingerprints` β pinning bypassed, walletβdaemon MITM
πΉ Severity: High
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: Monero
πΉ Reported By: benisprlh
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 5:06am (UTC)
π Source: HackerOne
The `set_daemon` JSON-RPC in `monero-wallet-rpc` was found to have a vulnerability that silently ignored the `ssl_allowed_fingerprints` parameter, allowing MITM attacks against the wallet-daemon connection. The vulnerability was introduced in the initial release of the RPC in March 2019 and affected all subsequent versions up to the latest release. The vulnerability was caused by improper handling of theβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: Monero
πΉ Reported By: benisprlh
πΉ State: π’ Resolved
πΉ Disclosed: August 5, 2026, 5:06am (UTC)
π Source: HackerOne
The `set_daemon` JSON-RPC in `monero-wallet-rpc` was found to have a vulnerability that silently ignored the `ssl_allowed_fingerprints` parameter, allowing MITM attacks against the wallet-daemon connection. The vulnerability was introduced in the initial release of the RPC in March 2019 and affected all subsequent versions up to the latest release. The vulnerability was caused by improper handling of theβ¦
π Read full report
Restricted RPC Policy Bypass on ZMQ JSON-RPC Allows Unauthenticated Remote Admin Actions
πΉ Severity: High
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Monero
πΉ Reported By: usagirabbit
πΉ State: π’ Resolved
πΉ Disclosed: August 17, 2026, 9:16am (UTC)
π Source: HackerOne
A high-severity access-control issue was found in Monero's ZMQ JSON-RPC surface. When the daemon is started in restricted/public-node mode, the HTTP RPC layer correctly suppresses admin-only methods, but the ZMQ JSON-RPC layer did not inherit or enforce that restriction. This allowed an unauthenticated remote client to invoke state-changing methods that should have been unavailable in restricted mode.
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Monero
πΉ Reported By: usagirabbit
πΉ State: π’ Resolved
πΉ Disclosed: August 17, 2026, 9:16am (UTC)
π Source: HackerOne
A high-severity access-control issue was found in Monero's ZMQ JSON-RPC surface. When the daemon is started in restricted/public-node mode, the HTTP RPC layer correctly suppresses admin-only methods, but the ZMQ JSON-RPC layer did not inherit or enforce that restriction. This allowed an unauthenticated remote client to invoke state-changing methods that should have been unavailable in restricted mode.
π Read full report
Wallet RPC Restricted-Mode Policy Bypass
πΉ Severity: High
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Monero
πΉ Reported By: usagirabbit
πΉ State: π’ Resolved
πΉ Disclosed: August 17, 2026, 9:16am (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero wallet RPC server that allowed restricted-mode clients to perform non-view-only operations. The issue was caused by inconsistent enforcement of the restricted mode, which allowed clients to bypass the intended view-only access controls and perform state-changing actions such as creating wallets, closing wallets, and mutating wallet state. The vulnerability was confirmedβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Monero
πΉ Reported By: usagirabbit
πΉ State: π’ Resolved
πΉ Disclosed: August 17, 2026, 9:16am (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero wallet RPC server that allowed restricted-mode clients to perform non-view-only operations. The issue was caused by inconsistent enforcement of the restricted mode, which allowed clients to bypass the intended view-only access controls and perform state-changing actions such as creating wallets, closing wallets, and mutating wallet state. The vulnerability was confirmedβ¦
π Read full report
URGENT: CRITICAL DATA BREACH - Cross-User PHI/PII Leakage via Prompt Injection - Non-malicious discovery
πΉ Severity: Critical
πΉ Reported To: OpenAI
πΉ Reported By: Teringette-adamuzonyi
πΉ State: π’ Resolved
πΉ Disclosed: August 19, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: OpenAI
πΉ Reported By: Teringette-adamuzonyi
πΉ State: π’ Resolved
πΉ Disclosed: August 19, 2026
π Source: Bugcrowd
π Read full report
Stored HTML Injection (CWE-79) via Livechat Visitor Name
πΉ Severity: Low
πΉ Weakness: Cross-site Scripting (XSS) - DOM
πΉ Reported To: Rocket.Chat
πΉ Reported By: hillng
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 7:18pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Weakness: Cross-site Scripting (XSS) - DOM
πΉ Reported To: Rocket.Chat
πΉ Reported By: hillng
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 7:18pm (UTC)
π Source: HackerOne
π Read full report
DDP methods getThreadsList / getThreadMessages leaks private thread content to any authenticated low privilege user (unpatched sibling of #1446767)
πΉ Severity: High
πΉ Weakness: NoSQL Injection
πΉ Reported To: Rocket.Chat
πΉ Reported By: iamaangx028
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 7:54pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: High
πΉ Weakness: NoSQL Injection
πΉ Reported To: Rocket.Chat
πΉ Reported By: iamaangx028
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 7:54pm (UTC)
π Source: HackerOne
π Read full report
Unauthenticated Error-Based SQL Injection via POST Parameter Name in /api/experiment/answer/new/
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: iaramsri
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: iaramsri
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026
π Source: Bugcrowd
π Read full report
Unauthenticated Remote Code Execution in NASA AMMOS AIT-GUI 2.5.0 via /tlm/query file write chained to /script/run code execution
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ward0
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: ward0
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026
π Source: Bugcrowd
π Read full report
Unauthenticated SSRF in NASA Trek addManifest allows internal network access from the Trek server
πΉ Severity: High
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: n0RollBack
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: High
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: n0RollBack
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026
π Source: Bugcrowd
π Read full report
Unauthorized Access to CI/CD Infrastructure and Project Secrets via Compromised GitLab Runner Token
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: oguzhan_00
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: oguzhan_00
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026
π Source: Bugcrowd
π Read full report
Loss of multisig funds through single malicious participant's deliberate deception
πΉ Severity: Medium
πΉ Weakness: Business Logic Errors
πΉ Reported To: Monero
πΉ Reported By: k-privacy-enjoyer
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:47pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero multisig implementation. A single malicious participant of a multisig could trick other users into sending funds multiple times to a certain recipient, which could not be easily distinguished from a legitimate user action. This issue was caused by the inability to view the inputs of partially signed multisig transactions, and the lack of a mechanism to deliberatelyβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Business Logic Errors
πΉ Reported To: Monero
πΉ Reported By: k-privacy-enjoyer
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:47pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero multisig implementation. A single malicious participant of a multisig could trick other users into sending funds multiple times to a certain recipient, which could not be easily distinguished from a legitimate user action. This issue was caused by the inability to view the inputs of partially signed multisig transactions, and the lack of a mechanism to deliberatelyβ¦
π Read full report
monero:// deeplink parsing accepts tx_amount=(all) and can trigger send-all transaction mode
πΉ Severity: Medium
πΉ Weakness: Business Logic Errors
πΉ Reported To: Monero
πΉ Reported By: qttps
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:47pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero GUI wallet application. The vulnerability allowed an attacker to craft a malicious URI that could be used to trigger a "send-all" transaction mode, where the victim's entire unlocked balance would be transferred to the attacker's address. The vulnerability was caused by improper validation of the "tx_amount" parameter in the external "monero://" URI handler, whichβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Business Logic Errors
πΉ Reported To: Monero
πΉ Reported By: qttps
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:47pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero GUI wallet application. The vulnerability allowed an attacker to craft a malicious URI that could be used to trigger a "send-all" transaction mode, where the victim's entire unlocked balance would be transferred to the attacker's address. The vulnerability was caused by improper validation of the "tx_amount" parameter in the external "monero://" URI handler, whichβ¦
π Read full report
Windows installer grants low-privileged users write access to executable P2Pool directory, enabling local code execution
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Monero
πΉ Reported By: qttps
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:47pm (UTC)
π Source: HackerOne
A Windows installer for the Monero GUI wallet created a subdirectory for P2Pool with overly broad write permissions for low-privileged users. The GUI later executed the `p2pool.exe` binary from that directory without any additional integrity checks, allowing a local attacker to plant malicious code that would be executed by the GUI.
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Monero
πΉ Reported By: qttps
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:47pm (UTC)
π Source: HackerOne
A Windows installer for the Monero GUI wallet created a subdirectory for P2Pool with overly broad write permissions for low-privileged users. The GUI later executed the `p2pool.exe` binary from that directory without any additional integrity checks, allowing a local attacker to plant malicious code that would be executed by the GUI.
π Read full report
HTML Injection in Transaction Confirmation Dialog via Address Book Description Enables UI Spoofing Before Fund Transfer
πΉ Severity: Medium
πΉ Weakness: Code Injection
πΉ Reported To: Monero
πΉ Reported By: fg0x0
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:49pm (UTC)
π Source: HackerOne
The Monero GUI wallet was found to render address book descriptions as HTML in the transaction confirmation dialog without sanitizing the input. This vulnerability could enable an attacker to craft a malicious Monero URI or QR code, which when added to the victim's address book, would display arbitrary HTML in the confirmation dialog before fund transfer. This could be used to spoof the recipient's details andβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Code Injection
πΉ Reported To: Monero
πΉ Reported By: fg0x0
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:49pm (UTC)
π Source: HackerOne
The Monero GUI wallet was found to render address book descriptions as HTML in the transaction confirmation dialog without sanitizing the input. This vulnerability could enable an attacker to craft a malicious Monero URI or QR code, which when added to the victim's address book, would display arbitrary HTML in the confirmation dialog before fund transfer. This could be used to spoof the recipient's details andβ¦
π Read full report
View-only offline transaction creation bypasses the long-payment-ID privacy block
πΉ Severity: Medium
πΉ Weakness: Information Disclosure
πΉ Reported To: Monero
πΉ Reported By: qttps
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:49pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the monero-gui wallet software where the view-only offline transaction creation process did not enforce the same protection against long payment IDs as the normal online transaction sending process. This allowed a malicious payment request to include a standalone payment ID, which could then be included in an unsigned offline transaction, potentially exposing the user's transactionβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Information Disclosure
πΉ Reported To: Monero
πΉ Reported By: qttps
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:49pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the monero-gui wallet software where the view-only offline transaction creation process did not enforce the same protection against long payment IDs as the normal online transaction sending process. This allowed a malicious payment request to include a standalone payment ID, which could then be included in an unsigned offline transaction, potentially exposing the user's transactionβ¦
π Read full report
Monero GUI OpenAlias DNSSEC-invalid resolution still writes spoofable address into recipient field
πΉ Severity: Medium
πΉ Reported To: Monero
πΉ Reported By: lilpeko
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:51pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero GUI that could allow an attacker to spoof the recipient address for a transaction. The vulnerability was caused by the GUI writing a potentially spoofed address to the recipient field, even when DNSSEC validation failed during an OpenAlias resolution. This could result in funds being sent to an attacker-controlled address if the user proceeded with the transaction.
π Read full report
πΉ Severity: Medium
πΉ Reported To: Monero
πΉ Reported By: lilpeko
πΉ State: π’ Resolved
πΉ Disclosed: August 20, 2026, 11:51pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Monero GUI that could allow an attacker to spoof the recipient address for a transaction. The vulnerability was caused by the GUI writing a potentially spoofed address to the recipient field, even when DNSSEC validation failed during an OpenAlias resolution. This could result in funds being sent to an attacker-controlled address if the user proceeded with the transaction.
π Read full report
Domainless COOKIEFILE cookie leaks to unrelated IP-literal hosts
πΉ Severity: No Rating
πΉ Weakness: Information Exposure Through Sent Data
πΉ Reported To: curl
πΉ Reported By: accl
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 21, 2026, 6:32am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Information Exposure Through Sent Data
πΉ Reported To: curl
πΉ Reported By: accl
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 21, 2026, 6:32am (UTC)
π Source: HackerOne
π Read full report
Path Traversal in Nextcloud Talk Android Exposes User Credentials and Private Data via FileProvider
πΉ Severity: Medium
πΉ Weakness: Path Traversal
πΉ Reported To: Nextcloud
πΉ Reported By: mirachael
πΉ State: π’ Resolved
πΉ Disclosed: August 24, 2026, 1:23am (UTC)
π Source: HackerOne
A vulnerability in Nextcloud Talk Android allowed an external Android app to write and retrieve config files by pinging an internal endpoint.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Path Traversal
πΉ Reported To: Nextcloud
πΉ Reported By: mirachael
πΉ State: π’ Resolved
πΉ Disclosed: August 24, 2026, 1:23am (UTC)
π Source: HackerOne
A vulnerability in Nextcloud Talk Android allowed an external Android app to write and retrieve config files by pinging an internal endpoint.
π Read full report
URI scheme validation bypass in ActionText `to_markdown` via user-supplied `<action-text-markdown>` marker tag
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Reflected
πΉ Reported To: Ruby on Rails
πΉ Reported By: offsetmd
πΉ State: π’ Resolved
πΉ Disclosed: August 24, 2026, 4:21pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Reflected
πΉ Reported To: Ruby on Rails
πΉ Reported By: offsetmd
πΉ State: π’ Resolved
πΉ Disclosed: August 24, 2026, 4:21pm (UTC)
π Source: HackerOne
π Read full report