Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization
πΉ Severity: Medium
πΉ Weakness: Insecure Direct Object Reference (IDOR)
πΉ Reported To: Discourse
πΉ Reported By: ahpuh
πΉ State: π’ Resolved
πΉ Disclosed: August 26, 2026, 5:47am (UTC)
π Source: HackerOne
A vulnerability was discovered in Discourse where a non-admin user with tag-editing permission could modify hidden or restricted tags by supplying their numeric IDs to the synonym creation and tag settings endpoints. Although the user could not view the hidden tags, the controller only authorized the visible target tag and did not re-check authorization for each synonym tag ID, allowing the non-admin user to updateβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Insecure Direct Object Reference (IDOR)
πΉ Reported To: Discourse
πΉ Reported By: ahpuh
πΉ State: π’ Resolved
πΉ Disclosed: August 26, 2026, 5:47am (UTC)
π Source: HackerOne
A vulnerability was discovered in Discourse where a non-admin user with tag-editing permission could modify hidden or restricted tags by supplying their numeric IDs to the synonym creation and tag settings endpoints. Although the user could not view the hidden tags, the controller only authorized the visible target tag and did not re-check authorization for each synonym tag ID, allowing the non-admin user to updateβ¦
π Read full report
curl_share TOCTOU > RCE via Curl_llist _dtor Function Pointer Hijack
πΉ Severity: Critical
πΉ Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πΉ Reported To: curl
πΉ Reported By: k4rasu_s4ma
πΉ State: π΄ N/A
πΉ Disclosed: August 26, 2026, 6:38am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Critical
πΉ Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πΉ Reported To: curl
πΉ Reported By: k4rasu_s4ma
πΉ State: π΄ N/A
πΉ Disclosed: August 26, 2026, 6:38am (UTC)
π Source: HackerOne
π Read full report
Critical SQL Injection WDM API (ββββββββ)
πΉ Severity: Critical
πΉ Weakness: SQL Injection
πΉ Reported To: Essity
πΉ Reported By: matty69v
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026, 7:23am (UTC)
π Source: HackerOne
A boolean-based and time-based blind SQL injection vulnerability was discovered in the searchText query parameter of the GET /api/WDMProduct endpoint. The vulnerability allowed an unauthenticated attacker to read or modify data in the backing Microsoft SQL Server database. The backend was found to be hosted on an Azure App Service and served by the in-scope Angular front-end application.
π Read full report
πΉ Severity: Critical
πΉ Weakness: SQL Injection
πΉ Reported To: Essity
πΉ Reported By: matty69v
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026, 7:23am (UTC)
π Source: HackerOne
A boolean-based and time-based blind SQL injection vulnerability was discovered in the searchText query parameter of the GET /api/WDMProduct endpoint. The vulnerability allowed an unauthenticated attacker to read or modify data in the backing Microsoft SQL Server database. The backend was found to be hosted on an Azure App Service and served by the in-scope Angular front-end application.
π Read full report
Pre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit)
πΉ Severity: Critical
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Essity
πΉ Reported By: matty69v
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026, 7:35am (UTC)
π Source: HackerOne
A pre-authentication stored cross-site scripting (XSS) vulnerability was discovered in the customer service API of the Essity company. The API accepted unauthenticated ticket submissions with arbitrary HTML/JavaScript in multiple fields, bypassing reCAPTCHA validation, CSRF protection, and rate limiting. When customer service operators viewed these tickets in the Umbraco back-office, the stored XSS executed inβ¦
π Read full report
πΉ Severity: Critical
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Essity
πΉ Reported By: matty69v
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026, 7:35am (UTC)
π Source: HackerOne
A pre-authentication stored cross-site scripting (XSS) vulnerability was discovered in the customer service API of the Essity company. The API accepted unauthenticated ticket submissions with arbitrary HTML/JavaScript in multiple fields, bypassing reCAPTCHA validation, CSRF protection, and rate limiting. When customer service operators viewed these tickets in the Umbraco back-office, the stored XSS executed inβ¦
π Read full report
ARG_CLEAR credential scrubbing wipes only UTF-8 copies on Windows Unicode builds
πΉ Severity: Low
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π΄ N/A
πΉ Disclosed: August 27, 2026, 8:21am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π΄ N/A
πΉ Disclosed: August 27, 2026, 8:21am (UTC)
π Source: HackerOne
π Read full report
Unbound cross-peer HTTP Digest challenge state
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 27, 2026, 8:21am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 27, 2026, 8:21am (UTC)
π Source: HackerOne
π Read full report
Unauthenticated Disclosure of Unpublished / Embargoed
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: 0xPewPew
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: 0xPewPew
πΉ State: π’ Resolved
πΉ Disclosed: August 27, 2026
π Source: Bugcrowd
π Read full report
Stacked --proto modifiers leave denied protocol enabled
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 8:22am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 8:22am (UTC)
π Source: HackerOne
π Read full report
--etag-save - truncates append-redirected stdout
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 8:22am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 8:22am (UTC)
π Source: HackerOne
π Read full report
34: `curl_mprintf` reads `double` for documented `long double` conversions β uninitialized value disclosure
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 9:33am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 9:33am (UTC)
π Source: HackerOne
π Read full report
28: HTTP/3 UDP path ignores CURL_SOCKOPT_ALREADY_CONNECTED, reconnects callback-provided socket
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 9:33am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 9:33am (UTC)
π Source: HackerOne
π Read full report
46: `--libcurl` output carries `--insecure` across `--next` boundaries
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 1:43pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: August 28, 2026, 1:43pm (UTC)
π Source: HackerOne
π Read full report
HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion
πΉ Severity: High
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Node.js
πΉ Reported By: leduckhuong
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:15pm (UTC)
π Source: HackerOne
A flaw in Node.js HTTP/2 handling was discovered that could cause HTTP/2 retained header blocks to evade the maxSessionMemory setting and enable remote memory exhaustion.
π Read full report
πΉ Severity: High
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Node.js
πΉ Reported By: leduckhuong
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:15pm (UTC)
π Source: HackerOne
A flaw in Node.js HTTP/2 handling was discovered that could cause HTTP/2 retained header blocks to evade the maxSessionMemory setting and enable remote memory exhaustion.
π Read full report
Re-entrant `nghttp2_session_mem_send()` during `nghttp2_session_mem_recv()` causes heap-use-after-free in Node.js HTTP/2
πΉ Severity: High
πΉ Weakness: Use After Free
πΉ Reported To: Node.js
πΉ Reported By: hahahkim
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:15pm (UTC)
π Source: HackerOne
A flaw was discovered in the Node.js HTTP/2 implementation that allowed the `nghttp2_session_mem_send()` function to be called re-entrantly while `nghttp2_session_mem_recv()` was executing, resulting in a heap-use-after-free vulnerability. This issue affected Node.js versions 26.x, 24.x, and 22.x.
π Read full report
πΉ Severity: High
πΉ Weakness: Use After Free
πΉ Reported To: Node.js
πΉ Reported By: hahahkim
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:15pm (UTC)
π Source: HackerOne
A flaw was discovered in the Node.js HTTP/2 implementation that allowed the `nghttp2_session_mem_send()` function to be called re-entrantly while `nghttp2_session_mem_recv()` was executing, resulting in a heap-use-after-free vulnerability. This issue affected Node.js versions 26.x, 24.x, and 22.x.
π Read full report
node:sqlite SQLTagStore Iterator Replay Lets Attacker Re-Execute Victim-Bound Writes Indefinitely
πΉ Severity: Medium
πΉ Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πΉ Reported To: Node.js
πΉ Reported By: cantina-security
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:15pm (UTC)
π Source: HackerOne
A flaw was discovered in the node:sqlite package for Node.js that allowed a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it had been reset and rebound with new parameters. The vulnerability was caused by the SQLTagStore feature resetting cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanismβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πΉ Reported To: Node.js
πΉ Reported By: cantina-security
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:15pm (UTC)
π Source: HackerOne
A flaw was discovered in the node:sqlite package for Node.js that allowed a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it had been reset and rebound with new parameters. The vulnerability was caused by the SQLTagStore feature resetting cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanismβ¦
π Read full report
dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records
πΉ Severity: Medium
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Node.js
πΉ Reported By: cantina-security
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:16pm (UTC)
π Source: HackerOne
A flaw in Node.js was discovered where the dns.resolveAny() function aborted the Node.js process when a DNS response contained more than 256 A records.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Node.js
πΉ Reported By: cantina-security
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:16pm (UTC)
π Source: HackerOne
A flaw in Node.js was discovered where the dns.resolveAny() function aborted the Node.js process when a DNS response contained more than 256 A records.
π Read full report
Reachable assertion in node:zlib sync API crashes the entire process via spoofed TypedArray byteLength (all 11 *Sync functions affected)
πΉ Severity: Medium
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Node.js
πΉ Reported By: byvini
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:16pm (UTC)
π Source: HackerOne
A flaw was discovered in the synchronous Node.js zlib APIs that allowed a spoofed TypedArray byteLength to trigger a reachable assertion, causing the entire process to crash. All 11 synchronous zlib functions were affected.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Node.js
πΉ Reported By: byvini
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:16pm (UTC)
π Source: HackerOne
A flaw was discovered in the synchronous Node.js zlib APIs that allowed a spoofed TypedArray byteLength to trigger a reachable assertion, causing the entire process to crash. All 11 synchronous zlib functions were affected.
π Read full report
HTTP Request Smuggling via Silent Header Truncation in Node.js HTTP Parser
πΉ Severity: Low
πΉ Weakness: HTTP Request Smuggling
πΉ Reported To: Node.js
πΉ Reported By: yushengchen
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:16pm (UTC)
π Source: HackerOne
A flaw in the Node.js HTTP client was discovered that could cause a request desynchronization for Node.js-based forwarding proxies. The issue was caused by the Node.js HTTP parser omitting headers beyond the configured limit from the visible request headers, while still using those headers internally for HTTP message framing. This vulnerability was found to affect all supported Node.js release lines.
π Read full report
πΉ Severity: Low
πΉ Weakness: HTTP Request Smuggling
πΉ Reported To: Node.js
πΉ Reported By: yushengchen
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 2:16pm (UTC)
π Source: HackerOne
A flaw in the Node.js HTTP client was discovered that could cause a request desynchronization for Node.js-based forwarding proxies. The issue was caused by the Node.js HTTP parser omitting headers beyond the configured limit from the visible request headers, while still using those headers internally for HTTP message framing. This vulnerability was found to affect all supported Node.js release lines.
π Read full report
Author β stored XSS in wp-admin: unescaped sub-size filename from attachment metadata breaks out of the `src` attribute in `get_media_item()`
πΉ Severity: Critical
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: WordPress
πΉ Reported By: jakubk
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 4:38pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the WordPress media upload and finalize endpoints. An author could upload a crafted image with a malicious filename, which was then stored verbatim by the endpoint and rendered without proper escaping in the WordPress admin media library. This could allow the execution of arbitrary JavaScript in the context of an administrator's browser session.
π Read full report
πΉ Severity: Critical
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: WordPress
πΉ Reported By: jakubk
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 4:38pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the WordPress media upload and finalize endpoints. An author could upload a crafted image with a malicious filename, which was then stored verbatim by the endpoint and rendered without proper escaping in the WordPress admin media library. This could allow the execution of arbitrary JavaScript in the context of an administrator's browser session.
π Read full report
Author β arbitrary file deletion anywhere on disk (site takeover) via `POST /wp/v2/media/<id>/finalize` poisoning `_wp_attachment_metadata`
πΉ Severity: Critical
πΉ Weakness: Path Traversal
πΉ Reported To: WordPress
πΉ Reported By: jakubk
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 4:39pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the WordPress media processing functionality. This vulnerability allowed an authenticated author to delete arbitrary files on the server. The vulnerability was caused by insufficient input validation in the `finalize_item()` function, which allowed an attacker to control the file paths stored in the attachment metadata. This resulted in the `wp_delete_attachment_files()` functionβ¦
π Read full report
πΉ Severity: Critical
πΉ Weakness: Path Traversal
πΉ Reported To: WordPress
πΉ Reported By: jakubk
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 4:39pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the WordPress media processing functionality. This vulnerability allowed an authenticated author to delete arbitrary files on the server. The vulnerability was caused by insufficient input validation in the `finalize_item()` function, which allowed an attacker to control the file paths stored in the attachment metadata. This resulted in the `wp_delete_attachment_files()` functionβ¦
π Read full report
Unauthorized vertical privilege escalation vulnerability found on ibm.com endpoint
πΉ Severity: No Rating
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: IBM
πΉ Reported By: inventor0x01
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 6:20pm (UTC)
π Source: HackerOne
A vertical privilege escalation vulnerability was found on an ibm.com endpoint. The vulnerability was reported to IBM, analyzed, and remediated.
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: IBM
πΉ Reported By: inventor0x01
πΉ State: π’ Resolved
πΉ Disclosed: August 28, 2026, 6:20pm (UTC)
π Source: HackerOne
A vertical privilege escalation vulnerability was found on an ibm.com endpoint. The vulnerability was reported to IBM, analyzed, and remediated.
π Read full report