Path Traversal in Nextcloud Talk Android Exposes User Credentials and Private Data via FileProvider
πΉ Severity: Medium
πΉ Weakness: Path Traversal
πΉ Reported To: Nextcloud
πΉ Reported By: mirachael
πΉ State: π’ Resolved
πΉ Disclosed: August 24, 2026, 1:23am (UTC)
π Source: HackerOne
A vulnerability in Nextcloud Talk Android allowed an external Android app to write and retrieve config files by pinging an internal endpoint.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Path Traversal
πΉ Reported To: Nextcloud
πΉ Reported By: mirachael
πΉ State: π’ Resolved
πΉ Disclosed: August 24, 2026, 1:23am (UTC)
π Source: HackerOne
A vulnerability in Nextcloud Talk Android allowed an external Android app to write and retrieve config files by pinging an internal endpoint.
π Read full report
URI scheme validation bypass in ActionText `to_markdown` via user-supplied `<action-text-markdown>` marker tag
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Reflected
πΉ Reported To: Ruby on Rails
πΉ Reported By: offsetmd
πΉ State: π’ Resolved
πΉ Disclosed: August 24, 2026, 4:21pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Reflected
πΉ Reported To: Ruby on Rails
πΉ Reported By: offsetmd
πΉ State: π’ Resolved
πΉ Disclosed: August 24, 2026, 4:21pm (UTC)
π Source: HackerOne
π Read full report
wolfSSL backend disables hostname verification when CURLOPT_SSL_VERIFYPEER is 0
πΉ Severity: Medium
πΉ Weakness: Improper Validation of Certificate with Host Mismatch
πΉ Reported To: curl
πΉ Reported By: subadevan
πΉ State: π΄ N/A
πΉ Disclosed: August 24, 2026, 9:51pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Improper Validation of Certificate with Host Mismatch
πΉ Reported To: curl
πΉ Reported By: subadevan
πΉ State: π΄ N/A
πΉ Disclosed: August 24, 2026, 9:51pm (UTC)
π Source: HackerOne
π Read full report
RTSP CRLF injection in libcurl allows CURLOPT_RTSP_* values to inject commands into independent sessions
πΉ Severity: Medium
πΉ Weakness: CRLF Injection
πΉ Reported To: curl
πΉ Reported By: subadevan
πΉ State: π΄ N/A
πΉ Disclosed: August 24, 2026, 9:51pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: CRLF Injection
πΉ Reported To: curl
πΉ Reported By: subadevan
πΉ State: π΄ N/A
πΉ Disclosed: August 24, 2026, 9:51pm (UTC)
π Source: HackerOne
π Read full report
@jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration)
πΉ Severity: Low
πΉ Weakness: Cross-site Scripting (XSS) - Generic
πΉ Reported To: 8x8
πΉ Reported By: a3z4km3
πΉ State: π’ Resolved
πΉ Disclosed: August 25, 2026, 2:09am (UTC)
π Source: HackerOne
An unsafe nginx regex pattern was discovered in the `/colibri-relay-ws/` location of the @jitsi/docker-jitsi-meet project. The regex `[a-zA-Z0-9-\\._]+` accepted arbitrary domain names and IP addresses for proxy_pass directives, allowing unauthenticated requests to be proxied to attacker-specified destinations. The vulnerable nginx location and associated relay WebSocket proxy configuration have been removed.
π Read full report
πΉ Severity: Low
πΉ Weakness: Cross-site Scripting (XSS) - Generic
πΉ Reported To: 8x8
πΉ Reported By: a3z4km3
πΉ State: π’ Resolved
πΉ Disclosed: August 25, 2026, 2:09am (UTC)
π Source: HackerOne
An unsafe nginx regex pattern was discovered in the `/colibri-relay-ws/` location of the @jitsi/docker-jitsi-meet project. The regex `[a-zA-Z0-9-\\._]+` accepted arbitrary domain names and IP addresses for proxy_pass directives, allowing unauthenticated requests to be proxied to attacker-specified destinations. The vulnerable nginx location and associated relay WebSocket proxy configuration have been removed.
π Read full report
libcurl Digest/NTLM authentication ignores an explicit Authorization header
πΉ Severity: Medium
πΉ Weakness: Incorrect Authorization
πΉ Reported To: curl
πΉ Reported By: subadevan
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 25, 2026, 1:26pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Incorrect Authorization
πΉ Reported To: curl
πΉ Reported By: subadevan
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 25, 2026, 1:26pm (UTC)
π Source: HackerOne
π Read full report
TLS session cache case-folds CA paths and bypasses the active trust profile
πΉ Severity: Medium
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 25, 2026, 5:21pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 25, 2026, 5:21pm (UTC)
π Source: HackerOne
π Read full report
Add labels to arbitrary issues/prs via Memex Bulk Update to compromise github actions label gating
πΉ Severity: Medium
πΉ Weakness: Insecure Direct Object Reference (IDOR)
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: August 25, 2026, 9:22pm (UTC)
π Source: HackerOne
A vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item to a project that already existed, column value updates were applied without verifying the actor's repository write permissions.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Insecure Direct Object Reference (IDOR)
πΉ Reported To: GitHub
πΉ Reported By: ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: August 25, 2026, 9:22pm (UTC)
π Source: HackerOne
A vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item to a project that already existed, column value updates were applied without verifying the actor's repository write permissions.
π Read full report
Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization
πΉ Severity: Medium
πΉ Weakness: Insecure Direct Object Reference (IDOR)
πΉ Reported To: Discourse
πΉ Reported By: ahpuh
πΉ State: π’ Resolved
πΉ Disclosed: August 26, 2026, 5:47am (UTC)
π Source: HackerOne
A vulnerability was discovered in Discourse where a non-admin user with tag-editing permission could modify hidden or restricted tags by supplying their numeric IDs to the synonym creation and tag settings endpoints. Although the user could not view the hidden tags, the controller only authorized the visible target tag and did not re-check authorization for each synonym tag ID, allowing the non-admin user to updateβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Insecure Direct Object Reference (IDOR)
πΉ Reported To: Discourse
πΉ Reported By: ahpuh
πΉ State: π’ Resolved
πΉ Disclosed: August 26, 2026, 5:47am (UTC)
π Source: HackerOne
A vulnerability was discovered in Discourse where a non-admin user with tag-editing permission could modify hidden or restricted tags by supplying their numeric IDs to the synonym creation and tag settings endpoints. Although the user could not view the hidden tags, the controller only authorized the visible target tag and did not re-check authorization for each synonym tag ID, allowing the non-admin user to updateβ¦
π Read full report
curl_share TOCTOU > RCE via Curl_llist _dtor Function Pointer Hijack
πΉ Severity: Critical
πΉ Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πΉ Reported To: curl
πΉ Reported By: k4rasu_s4ma
πΉ State: π΄ N/A
πΉ Disclosed: August 26, 2026, 6:38am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Critical
πΉ Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πΉ Reported To: curl
πΉ Reported By: k4rasu_s4ma
πΉ State: π΄ N/A
πΉ Disclosed: August 26, 2026, 6:38am (UTC)
π Source: HackerOne
π Read full report
Critical SQL Injection WDM API (ββββββββ)
πΉ Severity: Critical
πΉ Weakness: SQL Injection
πΉ Reported To: Essity
πΉ Reported By: matty69v
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026, 7:23am (UTC)
π Source: HackerOne
A boolean-based and time-based blind SQL injection vulnerability was discovered in the searchText query parameter of the GET /api/WDMProduct endpoint. The vulnerability allowed an unauthenticated attacker to read or modify data in the backing Microsoft SQL Server database. The backend was found to be hosted on an Azure App Service and served by the in-scope Angular front-end application.
π Read full report
πΉ Severity: Critical
πΉ Weakness: SQL Injection
πΉ Reported To: Essity
πΉ Reported By: matty69v
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026, 7:23am (UTC)
π Source: HackerOne
A boolean-based and time-based blind SQL injection vulnerability was discovered in the searchText query parameter of the GET /api/WDMProduct endpoint. The vulnerability allowed an unauthenticated attacker to read or modify data in the backing Microsoft SQL Server database. The backend was found to be hosted on an Azure App Service and served by the in-scope Angular front-end application.
π Read full report
Pre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit)
πΉ Severity: Critical
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Essity
πΉ Reported By: matty69v
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026, 7:35am (UTC)
π Source: HackerOne
A pre-authentication stored cross-site scripting (XSS) vulnerability was discovered in the customer service API of the Essity company. The API accepted unauthenticated ticket submissions with arbitrary HTML/JavaScript in multiple fields, bypassing reCAPTCHA validation, CSRF protection, and rate limiting. When customer service operators viewed these tickets in the Umbraco back-office, the stored XSS executed inβ¦
π Read full report
πΉ Severity: Critical
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Essity
πΉ Reported By: matty69v
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026, 7:35am (UTC)
π Source: HackerOne
A pre-authentication stored cross-site scripting (XSS) vulnerability was discovered in the customer service API of the Essity company. The API accepted unauthenticated ticket submissions with arbitrary HTML/JavaScript in multiple fields, bypassing reCAPTCHA validation, CSRF protection, and rate limiting. When customer service operators viewed these tickets in the Umbraco back-office, the stored XSS executed inβ¦
π Read full report
ARG_CLEAR credential scrubbing wipes only UTF-8 copies on Windows Unicode builds
πΉ Severity: Low
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π΄ N/A
πΉ Disclosed: August 27, 2026, 8:21am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π΄ N/A
πΉ Disclosed: August 27, 2026, 8:21am (UTC)
π Source: HackerOne
π Read full report
Unbound cross-peer HTTP Digest challenge state
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 27, 2026, 8:21am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 27, 2026, 8:21am (UTC)
π Source: HackerOne
π Read full report
Unauthenticated Disclosure of Unpublished / Embargoed
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: 0xPewPew
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: 0xPewPew
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026
π Source: Bugcrowd
π Read full report
Stacked --proto modifiers leave denied protocol enabled
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 8:22am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 8:22am (UTC)
π Source: HackerOne
π Read full report
--etag-save - truncates append-redirected stdout
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 8:22am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 8:22am (UTC)
π Source: HackerOne
π Read full report
34: `curl_mprintf` reads `double` for documented `long double` conversions β uninitialized value disclosure
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 9:33am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 9:33am (UTC)
π Source: HackerOne
π Read full report
28: HTTP/3 UDP path ignores CURL_SOCKOPT_ALREADY_CONNECTED, reconnects callback-provided socket
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 9:33am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 9:33am (UTC)
π Source: HackerOne
π Read full report
46: `--libcurl` output carries `--insecure` across `--next` boundaries
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 1:43pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 1:43pm (UTC)
π Source: HackerOne
π Read full report
HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion
πΉ Severity: High
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Node.js
πΉ Reported By: leduckhuong
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:15pm (UTC)
π Source: HackerOne
A flaw in Node.js HTTP/2 handling was discovered that could cause HTTP/2 retained header blocks to evade the maxSessionMemory setting and enable remote memory exhaustion.
π Read full report
πΉ Severity: High
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Node.js
πΉ Reported By: leduckhuong
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:15pm (UTC)
π Source: HackerOne
A flaw in Node.js HTTP/2 handling was discovered that could cause HTTP/2 retained header blocks to evade the maxSessionMemory setting and enable remote memory exhaustion.
π Read full report