Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
06: Incomplete fix for CVE-2026-7009: GCC/SecTrust builds silently discard stapled OCSP responses

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 31, 2026, 7:02am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
41: `main_checkfds()` pipe reuse leaks proxy credentials into HTTPS upload body

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Information Exposure Through Sent Data
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 31, 2026, 7:02am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
33: CONNECT_ONLY raw I/O selects wrong connection after CURLOPT_SHARE detach (incomplete fix for CVE-2020-8231)

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 31, 2026, 7:02am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
18: Explicit IPv6 proxy zone ID silently ignored β€” proxy credentials sent to wrong interface

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: August 31, 2026, 7:02am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unauthenticated Create, Read, and Delete of Any User's Data + Email Relay on JPL Hurricane Watch

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: Aman12321
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Unauthenticated OS Command Injection (RCE) in NASA International Mass Loading Service CGI (massloading.smce.nasa.gov /cgi-bin/eop_series.py)

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: radithyaputra
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
DOM-based cross-site scripting through the publicly exposed Cesium Sandcastle shared-code feature

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: iaramsri
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Publicly Accessible Administrative Configuration File Exposes Authentication Hashes and Internal Configuration

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: JulienZgh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Impersonation via Broken Link Hijacking on NASA Earth Matters Blog Page

πŸ”Ή Severity: Low
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: muhammadabdillah64edc3
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Ticket Trick Attack allows access to Rockstar Games' workspaces

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Rockstar Games
πŸ”Ή Reported By: recon_ninja
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026, 7:03pm (UTC)
🐞 Source: HackerOne

A vulnerability, referred to as "Ticket Trick Attack," was discovered in the support portal of Rockstar Games. The vulnerability allowed an attacker to gain unauthorized access to the company's workspaces by creating an account with an email address similar to the official support email address. This was possible because Rockstar Games did not properly validate the ownership of the email address before granting…

πŸ‘‰ Read full report
connect.8x8.com: Deserialization Vulnerability in Automation Builder via Jint→Newtonsoft serializer coercion (TypeNameHandling)

πŸ”Ή Severity: Critical | πŸ’° 3,000 USD
πŸ”Ή Weakness: Deserialization of Untrusted Data
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: kyotozzx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 1, 2026, 11:51pm (UTC)
🐞 Source: HackerOne

A deserialization vulnerability was reported in the 8x8 Connect Automation Builder's HTTP request step. The vulnerability occurred when server-side template evaluation exposed Newtonsoft JSON objects directly to the Jint JavaScript engine. By providing a specially crafted JSON response, an authenticated user could coerce Jint's overload resolution to construct a `JsonSerializer` with attacker-controlled…

πŸ‘‰ Read full report
connect.8x8.com: Automation Builder - Input Validation Issue in Workflow Step Outputs

πŸ”Ή Severity: High | πŸ’° 1,337 USD
πŸ”Ή Weakness: External Control of Critical State Data
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: kyotozzx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026, 12:03am (UTC)
🐞 Source: HackerOne

An input validation issue was reported in the 8x8 Connect Automation Builder's API where workflow step output field names were not validated against reserved context variable names. The issue was addressed by implementing validation to reject reserved field names at workflow creation.

πŸ‘‰ Read full report
07: GnuTLS 0-RTT early data bypasses file-backed public-key pin verification

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: September 2, 2026, 7:18am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
CVE-2026-18924: HTTP/2 server push UAF

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Use After Free
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: stze
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026, 7:44am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in libcurl versions 8.21.0 and later, where a use-after-free issue could occur in the HTTP/2 server push functionality. The vulnerability was caused by the fact that when a pushed transfer ends, the connection's pool is not properly handled, leading to the freed connection data being accessed later. The vulnerability was reproducible in a standalone program using the affected libcurl…

πŸ‘‰ Read full report
SSRF via URL Parser Differential in `normalize_request_url` (wlc)

πŸ”Ή Severity: High
πŸ”Ή Weakness: Server-Side Request Forgery (SSRF)
πŸ”Ή Reported To: Weblate
πŸ”Ή Reported By: dark_river
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026, 7:49am (UTC)
🐞 Source: HackerOne

The Weblate CLI client (wlc) was found to be vulnerable to Server-Side Request Forgery (SSRF) due to a differential in URL parsing between the urllib and urllib3 libraries. The vulnerability was present in the normalize_request_url function, which was meant to validate that outgoing API requests stayed on the configured server's origin. However, the actual HTTP request was dispatched by the requests library, which…

πŸ‘‰ Read full report
CVE-2026-80256: wcurl backslash bypass

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Path Traversal: '.../...//'
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026, 9:19am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the wcurl script of the curl project. The vulnerability allowed an attacker-controlled URL to create a new file outside the directory chosen by a Windows user, subject to the user's filesystem permissions and the target not already existing. The vulnerability was caused by the get_url_filename() function in the wcurl script, which protected percent-encoded characters but left a…

πŸ‘‰ Read full report
Command injection in Harmony trajectory-subsetter (subset.shape GeoJSON) gives any Earthdata user remote code execution (RCE) as root on harmony.earthdata.nasa.gov

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: cl45h
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
CVE-2026-13608: OpenLDAP SASL authentication bypass

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Authentication Bypass by Primary Weakness
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: hahahkim
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 12:35am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the OpenLDAP SASL authentication mechanism in libcurl. The vulnerability could allow a malicious LDAP server to bypass SASL authentication, potentially allowing the injection of arbitrary LDAP results. The vulnerable code has been present since the OpenLDAP SASL support was introduced and was unchanged in the current release.

πŸ‘‰ Read full report
CVE-2026-80255: secure cookie attribute bypass with tab

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Input Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:08am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
CVE-2026-82208: wolfSSL CA-cache hit overrides callback

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:08am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
CVE-2026-80231: native CA store conn reuse

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:08am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report