Impersonation via Broken Link Hijacking on NASA Earth Matters Blog Page
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: muhammadabdillah64edc3
πΉ State: π’ Resolved
πΉ Disclosed: September 1, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: muhammadabdillah64edc3
πΉ State: π’ Resolved
πΉ Disclosed: September 1, 2026
π Source: Bugcrowd
π Read full report
Ticket Trick Attack allows access to Rockstar Games' workspaces
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Rockstar Games
πΉ Reported By: recon_ninja
πΉ State: π’ Resolved
πΉ Disclosed: September 1, 2026, 7:03pm (UTC)
π Source: HackerOne
A vulnerability, referred to as "Ticket Trick Attack," was discovered in the support portal of Rockstar Games. The vulnerability allowed an attacker to gain unauthorized access to the company's workspaces by creating an account with an email address similar to the official support email address. This was possible because Rockstar Games did not properly validate the ownership of the email address before grantingβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Rockstar Games
πΉ Reported By: recon_ninja
πΉ State: π’ Resolved
πΉ Disclosed: September 1, 2026, 7:03pm (UTC)
π Source: HackerOne
A vulnerability, referred to as "Ticket Trick Attack," was discovered in the support portal of Rockstar Games. The vulnerability allowed an attacker to gain unauthorized access to the company's workspaces by creating an account with an email address similar to the official support email address. This was possible because Rockstar Games did not properly validate the ownership of the email address before grantingβ¦
π Read full report
connect.8x8.com: Deserialization Vulnerability in Automation Builder via JintβNewtonsoft serializer coercion (TypeNameHandling)
πΉ Severity: Critical | π° 3,000 USD
πΉ Weakness: Deserialization of Untrusted Data
πΉ Reported To: 8x8
πΉ Reported By: kyotozzx
πΉ State: π’ Resolved
πΉ Disclosed: September 1, 2026, 11:51pm (UTC)
π Source: HackerOne
A deserialization vulnerability was reported in the 8x8 Connect Automation Builder's HTTP request step. The vulnerability occurred when server-side template evaluation exposed Newtonsoft JSON objects directly to the Jint JavaScript engine. By providing a specially crafted JSON response, an authenticated user could coerce Jint's overload resolution to construct a `JsonSerializer` with attacker-controlledβ¦
π Read full report
πΉ Severity: Critical | π° 3,000 USD
πΉ Weakness: Deserialization of Untrusted Data
πΉ Reported To: 8x8
πΉ Reported By: kyotozzx
πΉ State: π’ Resolved
πΉ Disclosed: September 1, 2026, 11:51pm (UTC)
π Source: HackerOne
A deserialization vulnerability was reported in the 8x8 Connect Automation Builder's HTTP request step. The vulnerability occurred when server-side template evaluation exposed Newtonsoft JSON objects directly to the Jint JavaScript engine. By providing a specially crafted JSON response, an authenticated user could coerce Jint's overload resolution to construct a `JsonSerializer` with attacker-controlledβ¦
π Read full report
connect.8x8.com: Automation Builder - Input Validation Issue in Workflow Step Outputs
πΉ Severity: High | π° 1,337 USD
πΉ Weakness: External Control of Critical State Data
πΉ Reported To: 8x8
πΉ Reported By: kyotozzx
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026, 12:03am (UTC)
π Source: HackerOne
An input validation issue was reported in the 8x8 Connect Automation Builder's API where workflow step output field names were not validated against reserved context variable names. The issue was addressed by implementing validation to reject reserved field names at workflow creation.
π Read full report
πΉ Severity: High | π° 1,337 USD
πΉ Weakness: External Control of Critical State Data
πΉ Reported To: 8x8
πΉ Reported By: kyotozzx
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026, 12:03am (UTC)
π Source: HackerOne
An input validation issue was reported in the 8x8 Connect Automation Builder's API where workflow step output field names were not validated against reserved context variable names. The issue was addressed by implementing validation to reject reserved field names at workflow creation.
π Read full report
07: GnuTLS 0-RTT early data bypasses file-backed public-key pin verification
πΉ Severity: No Rating
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π΄ N/A
πΉ Disclosed: September 2, 2026, 7:18am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π΄ N/A
πΉ Disclosed: September 2, 2026, 7:18am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-18924: HTTP/2 server push UAF
πΉ Severity: Low
πΉ Weakness: Use After Free
πΉ Reported To: curl
πΉ Reported By: stze
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026, 7:44am (UTC)
π Source: HackerOne
A vulnerability was discovered in libcurl versions 8.21.0 and later, where a use-after-free issue could occur in the HTTP/2 server push functionality. The vulnerability was caused by the fact that when a pushed transfer ends, the connection's pool is not properly handled, leading to the freed connection data being accessed later. The vulnerability was reproducible in a standalone program using the affected libcurlβ¦
π Read full report
πΉ Severity: Low
πΉ Weakness: Use After Free
πΉ Reported To: curl
πΉ Reported By: stze
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026, 7:44am (UTC)
π Source: HackerOne
A vulnerability was discovered in libcurl versions 8.21.0 and later, where a use-after-free issue could occur in the HTTP/2 server push functionality. The vulnerability was caused by the fact that when a pushed transfer ends, the connection's pool is not properly handled, leading to the freed connection data being accessed later. The vulnerability was reproducible in a standalone program using the affected libcurlβ¦
π Read full report
SSRF via URL Parser Differential in `normalize_request_url` (wlc)
πΉ Severity: High
πΉ Weakness: Server-Side Request Forgery (SSRF)
πΉ Reported To: Weblate
πΉ Reported By: dark_river
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026, 7:49am (UTC)
π Source: HackerOne
The Weblate CLI client (wlc) was found to be vulnerable to Server-Side Request Forgery (SSRF) due to a differential in URL parsing between the urllib and urllib3 libraries. The vulnerability was present in the normalize_request_url function, which was meant to validate that outgoing API requests stayed on the configured server's origin. However, the actual HTTP request was dispatched by the requests library, whichβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Server-Side Request Forgery (SSRF)
πΉ Reported To: Weblate
πΉ Reported By: dark_river
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026, 7:49am (UTC)
π Source: HackerOne
The Weblate CLI client (wlc) was found to be vulnerable to Server-Side Request Forgery (SSRF) due to a differential in URL parsing between the urllib and urllib3 libraries. The vulnerability was present in the normalize_request_url function, which was meant to validate that outgoing API requests stayed on the configured server's origin. However, the actual HTTP request was dispatched by the requests library, whichβ¦
π Read full report
CVE-2026-80256: wcurl backslash bypass
πΉ Severity: Medium
πΉ Weakness: Path Traversal: '.../...//'
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026, 9:19am (UTC)
π Source: HackerOne
A vulnerability was discovered in the wcurl script of the curl project. The vulnerability allowed an attacker-controlled URL to create a new file outside the directory chosen by a Windows user, subject to the user's filesystem permissions and the target not already existing. The vulnerability was caused by the get_url_filename() function in the wcurl script, which protected percent-encoded characters but left aβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Path Traversal: '.../...//'
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026, 9:19am (UTC)
π Source: HackerOne
A vulnerability was discovered in the wcurl script of the curl project. The vulnerability allowed an attacker-controlled URL to create a new file outside the directory chosen by a Windows user, subject to the user's filesystem permissions and the target not already existing. The vulnerability was caused by the get_url_filename() function in the wcurl script, which protected percent-encoded characters but left aβ¦
π Read full report
Command injection in Harmony trajectory-subsetter (subset.shape GeoJSON) gives any Earthdata user remote code execution (RCE) as root on harmony.earthdata.nasa.gov
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: cl45h
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: cl45h
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2026
π Source: Bugcrowd
π Read full report
CVE-2026-13608: OpenLDAP SASL authentication bypass
πΉ Severity: Low
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: hahahkim
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 12:35am (UTC)
π Source: HackerOne
A vulnerability was discovered in the OpenLDAP SASL authentication mechanism in libcurl. The vulnerability could allow a malicious LDAP server to bypass SASL authentication, potentially allowing the injection of arbitrary LDAP results. The vulnerable code has been present since the OpenLDAP SASL support was introduced and was unchanged in the current release.
π Read full report
πΉ Severity: Low
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: hahahkim
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 12:35am (UTC)
π Source: HackerOne
A vulnerability was discovered in the OpenLDAP SASL authentication mechanism in libcurl. The vulnerability could allow a malicious LDAP server to bypass SASL authentication, potentially allowing the injection of arbitrary LDAP results. The vulnerable code has been present since the OpenLDAP SASL support was introduced and was unchanged in the current release.
π Read full report
CVE-2026-80255: secure cookie attribute bypass with tab
πΉ Severity: No Rating
πΉ Weakness: Improper Input Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Input Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-82208: wolfSSL CA-cache hit overrides callback
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-80231: native CA store conn reuse
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-80230: OpenSSL pinning bypass
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-80229: OpenSSL provider use-after-free
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-19931: Negotiate ambient user conn reuse
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: dukek
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: dukek
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-82209: domain-scoped PSL domain cookie
πΉ Severity: No Rating
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
Unauthorized Silent Webcam Activation via Loom Chrome Extension Web Accessible Resources
πΉ Severity: Medium
πΉ Reported To: Atlassian
πΉ Reported By: AlixSchaefer
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Medium
πΉ Reported To: Atlassian
πΉ Reported By: AlixSchaefer
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026
π Source: Bugcrowd
π Read full report
Stack Overflow DoS in ST_GeomFromGeoJSON Allows Any Authenticated User to Crash the Entire Server
πΉ Severity: Medium
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: byteoverride
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 10:13pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the MariaDB database server's ST_GeomFromGeoJSON function. Any authenticated user with basic SELECT privileges could crash the entire server by passing a deeply nested GeoJSON GeometryCollection. The crash was caused by unbounded recursion in the GeoJSON parser, which consumed the server's stack until it overflowed, leading to a SIGSEGV crash that killed all active connections andβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: byteoverride
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 10:13pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the MariaDB database server's ST_GeomFromGeoJSON function. Any authenticated user with basic SELECT privileges could crash the entire server by passing a deeply nested GeoJSON GeometryCollection. The crash was caused by unbounded recursion in the GeoJSON parser, which consumed the server's stack until it overflowed, leading to a SIGSEGV crash that killed all active connections andβ¦
π Read full report
Unauthenticated ?q= search query causes exponential pyparsing backtracking under a process-global lock in Weblate
πΉ Severity: High
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Weblate
πΉ Reported By: type5afe
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:10am (UTC)
π Source: HackerOne
A vulnerability was discovered in Weblate, an open-source translation management system. The vulnerability was caused by the search query grammar implementation in Weblate, which was built using the `pyparsing` library. The grammar was ambiguous at every position and did not enable memoization, leading to exponential backtracking during parsing of search queries with nested parentheses. This resulted in aβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Weblate
πΉ Reported By: type5afe
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:10am (UTC)
π Source: HackerOne
A vulnerability was discovered in Weblate, an open-source translation management system. The vulnerability was caused by the search query grammar implementation in Weblate, which was built using the `pyparsing` library. The grammar was ambiguous at every position and did not enable memoization, leading to exponential backtracking during parsing of search queries with nested parentheses. This resulted in aβ¦
π Read full report
API token sent to URL dictated by an untrusted project .weblate file
πΉ Severity: Medium
πΉ Weakness: Information Disclosure
πΉ Reported To: Weblate
πΉ Reported By: type5afe
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:10am (UTC)
π Source: HackerOne
A vulnerability was discovered in the wlc Python library used to interact with the Weblate translation management system. The vulnerability allowed an untrusted .weblate file to specify the Weblate API URL, which could then receive the API token set in the environment. The API token was resolved independently and was not bound to a trusted URL source, allowing the secret to be sent to an attacker-chosen server.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Information Disclosure
πΉ Reported To: Weblate
πΉ Reported By: type5afe
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:10am (UTC)
π Source: HackerOne
A vulnerability was discovered in the wlc Python library used to interact with the Weblate translation management system. The vulnerability allowed an untrusted .weblate file to specify the Weblate API URL, which could then receive the API token set in the environment. The API token was resolved independently and was not bound to a trusted URL source, allowing the secret to be sent to an attacker-chosen server.
π Read full report