Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Path Traversal in Nextcloud Talk Android Exposes User Credentials and Private Data via FileProvider

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Path Traversal
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: mirachael
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2026, 1:23am (UTC)
🐞 Source: HackerOne

A vulnerability in Nextcloud Talk Android allowed an external Android app to write and retrieve config files by pinging an internal endpoint.

πŸ‘‰ Read full report
URI scheme validation bypass in ActionText `to_markdown` via user-supplied `<action-text-markdown>` marker tag

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Reflected
πŸ”Ή Reported To: Ruby on Rails
πŸ”Ή Reported By: offsetmd
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 24, 2026, 4:21pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
wolfSSL backend disables hostname verification when CURLOPT_SSL_VERIFYPEER is 0

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Validation of Certificate with Host Mismatch
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: subadevan
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 24, 2026, 9:51pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
RTSP CRLF injection in libcurl allows CURLOPT_RTSP_* values to inject commands into independent sessions

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: CRLF Injection
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: subadevan
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 24, 2026, 9:51pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
@jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration)

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Generic
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: a3z4km3
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2026, 2:09am (UTC)
🐞 Source: HackerOne

An unsafe nginx regex pattern was discovered in the `/colibri-relay-ws/` location of the @jitsi/docker-jitsi-meet project. The regex `[a-zA-Z0-9-\\._]+` accepted arbitrary domain names and IP addresses for proxy_pass directives, allowing unauthenticated requests to be proxied to attacker-specified destinations. The vulnerable nginx location and associated relay WebSocket proxy configuration have been removed.

πŸ‘‰ Read full report
libcurl Digest/NTLM authentication ignores an explicit Authorization header

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Incorrect Authorization
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: subadevan
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 25, 2026, 1:26pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
TLS session cache case-folds CA paths and bypasses the active trust profile

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 25, 2026, 5:21pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Add labels to arbitrary issues/prs via Memex Bulk Update to compromise github actions label gating

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Insecure Direct Object Reference (IDOR)
πŸ”Ή Reported To: GitHub
πŸ”Ή Reported By: ahacker1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2026, 9:22pm (UTC)
🐞 Source: HackerOne

A vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item to a project that already existed, column value updates were applied without verifying the actor's repository write permissions.

πŸ‘‰ Read full report
Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Insecure Direct Object Reference (IDOR)
πŸ”Ή Reported To: Discourse
πŸ”Ή Reported By: ahpuh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2026, 5:47am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Discourse where a non-admin user with tag-editing permission could modify hidden or restricted tags by supplying their numeric IDs to the synonym creation and tag settings endpoints. Although the user could not view the hidden tags, the controller only authorized the visible target tag and did not re-check authorization for each synonym tag ID, allowing the non-admin user to update…

πŸ‘‰ Read full report
curl_share TOCTOU > RCE via Curl_llist _dtor Function Pointer Hijack

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: k4rasu_s4ma
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 26, 2026, 6:38am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Critical SQL Injection WDM API (β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ)

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: SQL Injection
πŸ”Ή Reported To: Essity
πŸ”Ή Reported By: matty69v
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2026, 7:23am (UTC)
🐞 Source: HackerOne

A boolean-based and time-based blind SQL injection vulnerability was discovered in the searchText query parameter of the GET /api/WDMProduct endpoint. The vulnerability allowed an unauthenticated attacker to read or modify data in the backing Microsoft SQL Server database. The backend was found to be hosted on an Azure App Service and served by the in-scope Angular front-end application.

πŸ‘‰ Read full report
Pre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit)

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: Essity
πŸ”Ή Reported By: matty69v
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2026, 7:35am (UTC)
🐞 Source: HackerOne

A pre-authentication stored cross-site scripting (XSS) vulnerability was discovered in the customer service API of the Essity company. The API accepted unauthenticated ticket submissions with arbitrary HTML/JavaScript in multiple fields, bypassing reCAPTCHA validation, CSRF protection, and rate limiting. When customer service operators viewed these tickets in the Umbraco back-office, the stored XSS executed in…

πŸ‘‰ Read full report
ARG_CLEAR credential scrubbing wipes only UTF-8 copies on Windows Unicode builds

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 27, 2026, 8:21am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unbound cross-peer HTTP Digest challenge state

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 27, 2026, 8:21am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unauthenticated Disclosure of Unpublished / Embargoed

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: 0xPewPew
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Stacked --proto modifiers leave denied protocol enabled

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 8:22am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
--etag-save - truncates append-redirected stdout

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 8:22am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
34: `curl_mprintf` reads `double` for documented `long double` conversions β€” uninitialized value disclosure

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 9:33am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
28: HTTP/3 UDP path ignores CURL_SOCKOPT_ALREADY_CONNECTED, reconnects callback-provided socket

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 9:33am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
46: `--libcurl` output carries `--insecure` across `--next` boundaries

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 1:43pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion

πŸ”Ή Severity: High
πŸ”Ή Weakness: Uncontrolled Resource Consumption
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: leduckhuong
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 2:15pm (UTC)
🐞 Source: HackerOne

A flaw in Node.js HTTP/2 handling was discovered that could cause HTTP/2 retained header blocks to evade the maxSessionMemory setting and enable remote memory exhaustion.

πŸ‘‰ Read full report