Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
CVE-2026-18924: HTTP/2 server push UAF

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Use After Free
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: stze
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026, 7:44am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in libcurl versions 8.21.0 and later, where a use-after-free issue could occur in the HTTP/2 server push functionality. The vulnerability was caused by the fact that when a pushed transfer ends, the connection's pool is not properly handled, leading to the freed connection data being accessed later. The vulnerability was reproducible in a standalone program using the affected libcurl…

πŸ‘‰ Read full report
SSRF via URL Parser Differential in `normalize_request_url` (wlc)

πŸ”Ή Severity: High
πŸ”Ή Weakness: Server-Side Request Forgery (SSRF)
πŸ”Ή Reported To: Weblate
πŸ”Ή Reported By: dark_river
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026, 7:49am (UTC)
🐞 Source: HackerOne

The Weblate CLI client (wlc) was found to be vulnerable to Server-Side Request Forgery (SSRF) due to a differential in URL parsing between the urllib and urllib3 libraries. The vulnerability was present in the normalize_request_url function, which was meant to validate that outgoing API requests stayed on the configured server's origin. However, the actual HTTP request was dispatched by the requests library, which…

πŸ‘‰ Read full report
CVE-2026-80256: wcurl backslash bypass

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Path Traversal: '.../...//'
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026, 9:19am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the wcurl script of the curl project. The vulnerability allowed an attacker-controlled URL to create a new file outside the directory chosen by a Windows user, subject to the user's filesystem permissions and the target not already existing. The vulnerability was caused by the get_url_filename() function in the wcurl script, which protected percent-encoded characters but left a…

πŸ‘‰ Read full report
Command injection in Harmony trajectory-subsetter (subset.shape GeoJSON) gives any Earthdata user remote code execution (RCE) as root on harmony.earthdata.nasa.gov

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: cl45h
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 2, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
CVE-2026-13608: OpenLDAP SASL authentication bypass

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Authentication Bypass by Primary Weakness
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: hahahkim
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 12:35am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the OpenLDAP SASL authentication mechanism in libcurl. The vulnerability could allow a malicious LDAP server to bypass SASL authentication, potentially allowing the injection of arbitrary LDAP results. The vulnerable code has been present since the OpenLDAP SASL support was introduced and was unchanged in the current release.

πŸ‘‰ Read full report
CVE-2026-80255: secure cookie attribute bypass with tab

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Input Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:08am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
CVE-2026-82208: wolfSSL CA-cache hit overrides callback

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:08am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
CVE-2026-80231: native CA store conn reuse

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:08am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
CVE-2026-80230: OpenSSL pinning bypass

πŸ”Ή Severity: None
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:08am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
CVE-2026-80229: OpenSSL provider use-after-free

πŸ”Ή Severity: None
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:09am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
CVE-2026-19931: Negotiate ambient user conn reuse

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Authentication Bypass by Primary Weakness
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: dukek
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:09am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
CVE-2026-82209: domain-scoped PSL domain cookie

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 6:09am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unauthorized Silent Webcam Activation via Loom Chrome Extension Web Accessible Resources

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Atlassian
πŸ”Ή Reported By: AlixSchaefer
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Stack Overflow DoS in ST_GeomFromGeoJSON Allows Any Authenticated User to Crash the Entire Server

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Stack Overflow
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: byteoverride
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 3, 2026, 10:13pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the MariaDB database server's ST_GeomFromGeoJSON function. Any authenticated user with basic SELECT privileges could crash the entire server by passing a deeply nested GeoJSON GeometryCollection. The crash was caused by unbounded recursion in the GeoJSON parser, which consumed the server's stack until it overflowed, leading to a SIGSEGV crash that killed all active connections and…

πŸ‘‰ Read full report
Unauthenticated ?q= search query causes exponential pyparsing backtracking under a process-global lock in Weblate

πŸ”Ή Severity: High
πŸ”Ή Weakness: Uncontrolled Resource Consumption
πŸ”Ή Reported To: Weblate
πŸ”Ή Reported By: type5afe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2026, 8:10am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Weblate, an open-source translation management system. The vulnerability was caused by the search query grammar implementation in Weblate, which was built using the `pyparsing` library. The grammar was ambiguous at every position and did not enable memoization, leading to exponential backtracking during parsing of search queries with nested parentheses. This resulted in a…

πŸ‘‰ Read full report
API token sent to URL dictated by an untrusted project .weblate file

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: Weblate
πŸ”Ή Reported By: type5afe
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2026, 8:10am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the wlc Python library used to interact with the Weblate translation management system. The vulnerability allowed an untrusted .weblate file to specify the Weblate API URL, which could then receive the API token set in the environment. The API token was resolved independently and was not bound to a trusted URL source, allowing the secret to be sent to an attacker-chosen server.

πŸ‘‰ Read full report
Mail contact autocomplete bypasses administrator-configured user enumeration restrictions and expose member information outside the intended scope

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Privacy Violation
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: njh215
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 4, 2026, 8:38pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the Mail contact autocomplete feature of Nextcloud that allowed an authenticated user to bypass administrator-configured user enumeration restrictions and expose member information outside the intended scope. The vulnerability was present in the `ContactIntegrationController::autoComplete()` handler, which did not apply the stricter user enumeration controls used elsewhere in the…

πŸ‘‰ Read full report
Activity app does not verify federated file activity received from remote servers

πŸ”Ή Severity: Low | πŸ’° 150 USD
πŸ”Ή Weakness: Improper Authentication - Generic
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: cyebrsunita
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2026, 2:18pm (UTC)
🐞 Source: HackerOne

The activity app stored activity content received from remote servers without verifying the content first.

πŸ‘‰ Read full report
Missing Duplicate Check allowing Multiple Retention Rules per System Tag

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Business Logic Errors
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: charankumar39
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2026, 2:23pm (UTC)
🐞 Source: HackerOne

A bug allowed admins to create multiple retention rules for the same tag, causing potential confusion for other admins.

πŸ‘‰ Read full report
Improper Input Validation and Integer Overflow in timeamount parameter of files_retention app

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Integer Overflow
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: nishantbaswal1996
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2026, 2:29pm (UTC)
🐞 Source: HackerOne

The timeamount parameter of the files_retention app lacked proper input validation, allowing an administrator to store an unintended long time amount as the retention period. This vulnerability could have potentially led to files never getting deleted.

πŸ‘‰ Read full report
Email Enumeration via Password-Protected Share Identity Verification

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: cybershinu90
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2026, 2:38pm (UTC)
🐞 Source: HackerOne

The vulnerability allowed email enumeration through password-protected share identity verification. Requesting a password for an email share resulted in different response messages depending on whether the email address was the intended recipient, enabling confirmation of the share recipient.

πŸ‘‰ Read full report