Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Insecure Direct Object Reference (IDOR)
πŸ”Ή Reported To: Discourse
πŸ”Ή Reported By: ahpuh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2026, 5:47am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Discourse where a non-admin user with tag-editing permission could modify hidden or restricted tags by supplying their numeric IDs to the synonym creation and tag settings endpoints. Although the user could not view the hidden tags, the controller only authorized the visible target tag and did not re-check authorization for each synonym tag ID, allowing the non-admin user to update…

πŸ‘‰ Read full report
curl_share TOCTOU > RCE via Curl_llist _dtor Function Pointer Hijack

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: k4rasu_s4ma
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 26, 2026, 6:38am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Critical SQL Injection WDM API (β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ)

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: SQL Injection
πŸ”Ή Reported To: Essity
πŸ”Ή Reported By: matty69v
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2026, 7:23am (UTC)
🐞 Source: HackerOne

A boolean-based and time-based blind SQL injection vulnerability was discovered in the searchText query parameter of the GET /api/WDMProduct endpoint. The vulnerability allowed an unauthenticated attacker to read or modify data in the backing Microsoft SQL Server database. The backend was found to be hosted on an Azure App Service and served by the in-scope Angular front-end application.

πŸ‘‰ Read full report
Pre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit)

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: Essity
πŸ”Ή Reported By: matty69v
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2026, 7:35am (UTC)
🐞 Source: HackerOne

A pre-authentication stored cross-site scripting (XSS) vulnerability was discovered in the customer service API of the Essity company. The API accepted unauthenticated ticket submissions with arbitrary HTML/JavaScript in multiple fields, bypassing reCAPTCHA validation, CSRF protection, and rate limiting. When customer service operators viewed these tickets in the Umbraco back-office, the stored XSS executed in…

πŸ‘‰ Read full report
ARG_CLEAR credential scrubbing wipes only UTF-8 copies on Windows Unicode builds

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: August 27, 2026, 8:21am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unbound cross-peer HTTP Digest challenge state

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 27, 2026, 8:21am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unauthenticated Disclosure of Unpublished / Embargoed

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: 0xPewPew
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Stacked --proto modifiers leave denied protocol enabled

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 8:22am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
--etag-save - truncates append-redirected stdout

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 8:22am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
34: `curl_mprintf` reads `double` for documented `long double` conversions β€” uninitialized value disclosure

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 9:33am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
28: HTTP/3 UDP path ignores CURL_SOCKOPT_ALREADY_CONNECTED, reconnects callback-provided socket

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 9:33am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
46: `--libcurl` output carries `--insecure` across `--next` boundaries

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 28, 2026, 1:43pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion

πŸ”Ή Severity: High
πŸ”Ή Weakness: Uncontrolled Resource Consumption
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: leduckhuong
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 2:15pm (UTC)
🐞 Source: HackerOne

A flaw in Node.js HTTP/2 handling was discovered that could cause HTTP/2 retained header blocks to evade the maxSessionMemory setting and enable remote memory exhaustion.

πŸ‘‰ Read full report
Re-entrant `nghttp2_session_mem_send()` during `nghttp2_session_mem_recv()` causes heap-use-after-free in Node.js HTTP/2

πŸ”Ή Severity: High
πŸ”Ή Weakness: Use After Free
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: hahahkim
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 2:15pm (UTC)
🐞 Source: HackerOne

A flaw was discovered in the Node.js HTTP/2 implementation that allowed the `nghttp2_session_mem_send()` function to be called re-entrantly while `nghttp2_session_mem_recv()` was executing, resulting in a heap-use-after-free vulnerability. This issue affected Node.js versions 26.x, 24.x, and 22.x.

πŸ‘‰ Read full report
node:sqlite SQLTagStore Iterator Replay Lets Attacker Re-Execute Victim-Bound Writes Indefinitely

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Time-of-check Time-of-use (TOCTOU) Race Condition
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: cantina-security
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 2:15pm (UTC)
🐞 Source: HackerOne

A flaw was discovered in the node:sqlite package for Node.js that allowed a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it had been reset and rebound with new parameters. The vulnerability was caused by the SQLTagStore feature resetting cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanism…

πŸ‘‰ Read full report
dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Uncontrolled Resource Consumption
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: cantina-security
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 2:16pm (UTC)
🐞 Source: HackerOne

A flaw in Node.js was discovered where the dns.resolveAny() function aborted the Node.js process when a DNS response contained more than 256 A records.

πŸ‘‰ Read full report
Reachable assertion in node:zlib sync API crashes the entire process via spoofed TypedArray byteLength (all 11 *Sync functions affected)

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Uncontrolled Resource Consumption
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: byvini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 2:16pm (UTC)
🐞 Source: HackerOne

A flaw was discovered in the synchronous Node.js zlib APIs that allowed a spoofed TypedArray byteLength to trigger a reachable assertion, causing the entire process to crash. All 11 synchronous zlib functions were affected.

πŸ‘‰ Read full report
HTTP Request Smuggling via Silent Header Truncation in Node.js HTTP Parser

πŸ”Ή Severity: Low
πŸ”Ή Weakness: HTTP Request Smuggling
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: yushengchen
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 2:16pm (UTC)
🐞 Source: HackerOne

A flaw in the Node.js HTTP client was discovered that could cause a request desynchronization for Node.js-based forwarding proxies. The issue was caused by the Node.js HTTP parser omitting headers beyond the configured limit from the visible request headers, while still using those headers internally for HTTP message framing. This vulnerability was found to affect all supported Node.js release lines.

πŸ‘‰ Read full report
Author β†’ stored XSS in wp-admin: unescaped sub-size filename from attachment metadata breaks out of the `src` attribute in `get_media_item()`

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: WordPress
πŸ”Ή Reported By: jakubk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 4:38pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the WordPress media upload and finalize endpoints. An author could upload a crafted image with a malicious filename, which was then stored verbatim by the endpoint and rendered without proper escaping in the WordPress admin media library. This could allow the execution of arbitrary JavaScript in the context of an administrator's browser session.

πŸ‘‰ Read full report
Author β†’ arbitrary file deletion anywhere on disk (site takeover) via `POST /wp/v2/media/<id>/finalize` poisoning `_wp_attachment_metadata`

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Path Traversal
πŸ”Ή Reported To: WordPress
πŸ”Ή Reported By: jakubk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 4:39pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the WordPress media processing functionality. This vulnerability allowed an authenticated author to delete arbitrary files on the server. The vulnerability was caused by insufficient input validation in the `finalize_item()` function, which allowed an attacker to control the file paths stored in the attachment metadata. This resulted in the `wp_delete_attachment_files()` function…

πŸ‘‰ Read full report
Unauthorized vertical privilege escalation vulnerability found on ibm.com endpoint

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: IBM
πŸ”Ή Reported By: inventor0x01
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 6:20pm (UTC)
🐞 Source: HackerOne

A vertical privilege escalation vulnerability was found on an ibm.com endpoint. The vulnerability was reported to IBM, analyzed, and remediated.

πŸ‘‰ Read full report