Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Reachable assertion in node:zlib sync API crashes the entire process via spoofed TypedArray byteLength (all 11 *Sync functions affected)

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Uncontrolled Resource Consumption
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: byvini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 2:16pm (UTC)
🐞 Source: HackerOne

A flaw was discovered in the synchronous Node.js zlib APIs that allowed a spoofed TypedArray byteLength to trigger a reachable assertion, causing the entire process to crash. All 11 synchronous zlib functions were affected.

πŸ‘‰ Read full report
HTTP Request Smuggling via Silent Header Truncation in Node.js HTTP Parser

πŸ”Ή Severity: Low
πŸ”Ή Weakness: HTTP Request Smuggling
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: yushengchen
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 2:16pm (UTC)
🐞 Source: HackerOne

A flaw in the Node.js HTTP client was discovered that could cause a request desynchronization for Node.js-based forwarding proxies. The issue was caused by the Node.js HTTP parser omitting headers beyond the configured limit from the visible request headers, while still using those headers internally for HTTP message framing. This vulnerability was found to affect all supported Node.js release lines.

πŸ‘‰ Read full report
Author β†’ stored XSS in wp-admin: unescaped sub-size filename from attachment metadata breaks out of the `src` attribute in `get_media_item()`

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: WordPress
πŸ”Ή Reported By: jakubk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 4:38pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the WordPress media upload and finalize endpoints. An author could upload a crafted image with a malicious filename, which was then stored verbatim by the endpoint and rendered without proper escaping in the WordPress admin media library. This could allow the execution of arbitrary JavaScript in the context of an administrator's browser session.

πŸ‘‰ Read full report
Author β†’ arbitrary file deletion anywhere on disk (site takeover) via `POST /wp/v2/media/<id>/finalize` poisoning `_wp_attachment_metadata`

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Path Traversal
πŸ”Ή Reported To: WordPress
πŸ”Ή Reported By: jakubk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 4:39pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the WordPress media processing functionality. This vulnerability allowed an authenticated author to delete arbitrary files on the server. The vulnerability was caused by insufficient input validation in the `finalize_item()` function, which allowed an attacker to control the file paths stored in the attachment metadata. This resulted in the `wp_delete_attachment_files()` function…

πŸ‘‰ Read full report
Unauthorized vertical privilege escalation vulnerability found on ibm.com endpoint

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: IBM
πŸ”Ή Reported By: inventor0x01
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 28, 2026, 6:20pm (UTC)
🐞 Source: HackerOne

A vertical privilege escalation vulnerability was found on an ibm.com endpoint. The vulnerability was reported to IBM, analyzed, and remediated.

πŸ‘‰ Read full report
42: `VMS_STS` macro typo (`< 3` vs `<< 3`) turns curl failures into successful OpenVMS conditions

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Check or Handling of Exceptional Conditions
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 29, 2026, 12:48pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
50: CMake `HTTP_ONLY` does not disable SSH backends β€” SCP and SFTP remain usable

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Server-Side Request Forgery (SSRF)
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 29, 2026, 12:51pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
**Unauthenticated IDOR allows modification of payment customer billing information**

πŸ”Ή Severity: High
πŸ”Ή Weakness: Insecure Direct Object Reference (IDOR)
πŸ”Ή Reported To: Weblate
πŸ”Ή Reported By: visionx7
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 30, 2026, 4:54am (UTC)
🐞 Source: HackerOne

The application contained an access control issue in the payment billing information edit functionality. An unauthenticated user was able to access the payment edit endpoint and modify the billing information associated with a payment without any authorization check. The issue occurred because the application allowed access to the edit page using only the payment identifier in the URL, and the server did not verify…

πŸ‘‰ Read full report
06: Incomplete fix for CVE-2026-7009: GCC/SecTrust builds silently discard stapled OCSP responses

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 31, 2026, 7:02am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
41: `main_checkfds()` pipe reuse leaks proxy credentials into HTTPS upload body

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Information Exposure Through Sent Data
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 31, 2026, 7:02am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
33: CONNECT_ONLY raw I/O selects wrong connection after CURLOPT_SHARE detach (incomplete fix for CVE-2020-8231)

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 31, 2026, 7:02am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
18: Explicit IPv6 proxy zone ID silently ignored β€” proxy credentials sent to wrong interface

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 31, 2026, 7:02am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unauthenticated Create, Read, and Delete of Any User's Data + Email Relay on JPL Hurricane Watch

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: Aman12321
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Unauthenticated OS Command Injection (RCE) in NASA International Mass Loading Service CGI (massloading.smce.nasa.gov /cgi-bin/eop_series.py)

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: radithyaputra
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
DOM-based cross-site scripting through the publicly exposed Cesium Sandcastle shared-code feature

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: iaramsri
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Publicly Accessible Administrative Configuration File Exposes Authentication Hashes and Internal Configuration

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: JulienZgh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Impersonation via Broken Link Hijacking on NASA Earth Matters Blog Page

πŸ”Ή Severity: Low
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: muhammadabdillah64edc3
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Ticket Trick Attack allows access to Rockstar Games' workspaces

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Rockstar Games
πŸ”Ή Reported By: recon_ninja
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026, 7:03pm (UTC)
🐞 Source: HackerOne

A vulnerability, referred to as "Ticket Trick Attack," was discovered in the support portal of Rockstar Games. The vulnerability allowed an attacker to gain unauthorized access to the company's workspaces by creating an account with an email address similar to the official support email address. This was possible because Rockstar Games did not properly validate the ownership of the email address before granting…

πŸ‘‰ Read full report
connect.8x8.com: Deserialization Vulnerability in Automation Builder via Jint→Newtonsoft serializer coercion (TypeNameHandling)

πŸ”Ή Severity: Critical | πŸ’° 3,000 USD
πŸ”Ή Weakness: Deserialization of Untrusted Data
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: kyotozzx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026, 11:51pm (UTC)
🐞 Source: HackerOne

A deserialization vulnerability was reported in the 8x8 Connect Automation Builder's HTTP request step. The vulnerability occurred when server-side template evaluation exposed Newtonsoft JSON objects directly to the Jint JavaScript engine. By providing a specially crafted JSON response, an authenticated user could coerce Jint's overload resolution to construct a `JsonSerializer` with attacker-controlled…

πŸ‘‰ Read full report
connect.8x8.com: Automation Builder - Input Validation Issue in Workflow Step Outputs

πŸ”Ή Severity: High | πŸ’° 1,337 USD
πŸ”Ή Weakness: External Control of Critical State Data
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: kyotozzx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026, 12:03am (UTC)
🐞 Source: HackerOne

An input validation issue was reported in the 8x8 Connect Automation Builder's API where workflow step output field names were not validated against reserved context variable names. The issue was addressed by implementing validation to reject reserved field names at workflow creation.

πŸ‘‰ Read full report
07: GnuTLS 0-RTT early data bypasses file-backed public-key pin verification

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: September 2, 2026, 7:18am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report