CVE-2026-13608: OpenLDAP SASL authentication bypass
πΉ Severity: Low
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: hahahkim
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 12:35am (UTC)
π Source: HackerOne
A vulnerability was discovered in the OpenLDAP SASL authentication mechanism in libcurl. The vulnerability could allow a malicious LDAP server to bypass SASL authentication, potentially allowing the injection of arbitrary LDAP results. The vulnerable code has been present since the OpenLDAP SASL support was introduced and was unchanged in the current release.
π Read full report
πΉ Severity: Low
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: hahahkim
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 12:35am (UTC)
π Source: HackerOne
A vulnerability was discovered in the OpenLDAP SASL authentication mechanism in libcurl. The vulnerability could allow a malicious LDAP server to bypass SASL authentication, potentially allowing the injection of arbitrary LDAP results. The vulnerable code has been present since the OpenLDAP SASL support was introduced and was unchanged in the current release.
π Read full report
CVE-2026-80255: secure cookie attribute bypass with tab
πΉ Severity: No Rating
πΉ Weakness: Improper Input Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Input Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-82208: wolfSSL CA-cache hit overrides callback
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-80231: native CA store conn reuse
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-80230: OpenSSL pinning bypass
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:08am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-80229: OpenSSL provider use-after-free
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-19931: Negotiate ambient user conn reuse
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: dukek
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: dukek
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
CVE-2026-82209: domain-scoped PSL domain cookie
πΉ Severity: No Rating
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Information Disclosure
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 6:09am (UTC)
π Source: HackerOne
π Read full report
Unauthorized Silent Webcam Activation via Loom Chrome Extension Web Accessible Resources
πΉ Severity: Medium
πΉ Reported To: Atlassian
πΉ Reported By: AlixSchaefer
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Medium
πΉ Reported To: Atlassian
πΉ Reported By: AlixSchaefer
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026
π Source: Bugcrowd
π Read full report
Stack Overflow DoS in ST_GeomFromGeoJSON Allows Any Authenticated User to Crash the Entire Server
πΉ Severity: Medium
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: byteoverride
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 10:13pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the MariaDB database server's ST_GeomFromGeoJSON function. Any authenticated user with basic SELECT privileges could crash the entire server by passing a deeply nested GeoJSON GeometryCollection. The crash was caused by unbounded recursion in the GeoJSON parser, which consumed the server's stack until it overflowed, leading to a SIGSEGV crash that killed all active connections andβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: byteoverride
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2026, 10:13pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the MariaDB database server's ST_GeomFromGeoJSON function. Any authenticated user with basic SELECT privileges could crash the entire server by passing a deeply nested GeoJSON GeometryCollection. The crash was caused by unbounded recursion in the GeoJSON parser, which consumed the server's stack until it overflowed, leading to a SIGSEGV crash that killed all active connections andβ¦
π Read full report
Unauthenticated ?q= search query causes exponential pyparsing backtracking under a process-global lock in Weblate
πΉ Severity: High
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Weblate
πΉ Reported By: type5afe
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:10am (UTC)
π Source: HackerOne
A vulnerability was discovered in Weblate, an open-source translation management system. The vulnerability was caused by the search query grammar implementation in Weblate, which was built using the `pyparsing` library. The grammar was ambiguous at every position and did not enable memoization, leading to exponential backtracking during parsing of search queries with nested parentheses. This resulted in aβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Weblate
πΉ Reported By: type5afe
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:10am (UTC)
π Source: HackerOne
A vulnerability was discovered in Weblate, an open-source translation management system. The vulnerability was caused by the search query grammar implementation in Weblate, which was built using the `pyparsing` library. The grammar was ambiguous at every position and did not enable memoization, leading to exponential backtracking during parsing of search queries with nested parentheses. This resulted in aβ¦
π Read full report
API token sent to URL dictated by an untrusted project .weblate file
πΉ Severity: Medium
πΉ Weakness: Information Disclosure
πΉ Reported To: Weblate
πΉ Reported By: type5afe
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:10am (UTC)
π Source: HackerOne
A vulnerability was discovered in the wlc Python library used to interact with the Weblate translation management system. The vulnerability allowed an untrusted .weblate file to specify the Weblate API URL, which could then receive the API token set in the environment. The API token was resolved independently and was not bound to a trusted URL source, allowing the secret to be sent to an attacker-chosen server.
π Read full report
πΉ Severity: Medium
πΉ Weakness: Information Disclosure
πΉ Reported To: Weblate
πΉ Reported By: type5afe
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:10am (UTC)
π Source: HackerOne
A vulnerability was discovered in the wlc Python library used to interact with the Weblate translation management system. The vulnerability allowed an untrusted .weblate file to specify the Weblate API URL, which could then receive the API token set in the environment. The API token was resolved independently and was not bound to a trusted URL source, allowing the secret to be sent to an attacker-chosen server.
π Read full report
Mail contact autocomplete bypasses administrator-configured user enumeration restrictions and expose member information outside the intended scope
πΉ Severity: Medium
πΉ Weakness: Privacy Violation
πΉ Reported To: Nextcloud
πΉ Reported By: njh215
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:38pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Mail contact autocomplete feature of Nextcloud that allowed an authenticated user to bypass administrator-configured user enumeration restrictions and expose member information outside the intended scope. The vulnerability was present in the `ContactIntegrationController::autoComplete()` handler, which did not apply the stricter user enumeration controls used elsewhere in theβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Privacy Violation
πΉ Reported To: Nextcloud
πΉ Reported By: njh215
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2026, 8:38pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the Mail contact autocomplete feature of Nextcloud that allowed an authenticated user to bypass administrator-configured user enumeration restrictions and expose member information outside the intended scope. The vulnerability was present in the `ContactIntegrationController::autoComplete()` handler, which did not apply the stricter user enumeration controls used elsewhere in theβ¦
π Read full report
Activity app does not verify federated file activity received from remote servers
πΉ Severity: Low | π° 150 USD
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Nextcloud
πΉ Reported By: cyebrsunita
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:18pm (UTC)
π Source: HackerOne
The activity app stored activity content received from remote servers without verifying the content first.
π Read full report
πΉ Severity: Low | π° 150 USD
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Nextcloud
πΉ Reported By: cyebrsunita
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:18pm (UTC)
π Source: HackerOne
The activity app stored activity content received from remote servers without verifying the content first.
π Read full report
Missing Duplicate Check allowing Multiple Retention Rules per System Tag
πΉ Severity: Low
πΉ Weakness: Business Logic Errors
πΉ Reported To: Nextcloud
πΉ Reported By: charankumar39
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:23pm (UTC)
π Source: HackerOne
A bug allowed admins to create multiple retention rules for the same tag, causing potential confusion for other admins.
π Read full report
πΉ Severity: Low
πΉ Weakness: Business Logic Errors
πΉ Reported To: Nextcloud
πΉ Reported By: charankumar39
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:23pm (UTC)
π Source: HackerOne
A bug allowed admins to create multiple retention rules for the same tag, causing potential confusion for other admins.
π Read full report
Improper Input Validation and Integer Overflow in timeamount parameter of files_retention app
πΉ Severity: Low
πΉ Weakness: Integer Overflow
πΉ Reported To: Nextcloud
πΉ Reported By: nishantbaswal1996
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:29pm (UTC)
π Source: HackerOne
The timeamount parameter of the files_retention app lacked proper input validation, allowing an administrator to store an unintended long time amount as the retention period. This vulnerability could have potentially led to files never getting deleted.
π Read full report
πΉ Severity: Low
πΉ Weakness: Integer Overflow
πΉ Reported To: Nextcloud
πΉ Reported By: nishantbaswal1996
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:29pm (UTC)
π Source: HackerOne
The timeamount parameter of the files_retention app lacked proper input validation, allowing an administrator to store an unintended long time amount as the retention period. This vulnerability could have potentially led to files never getting deleted.
π Read full report
Email Enumeration via Password-Protected Share Identity Verification
πΉ Severity: Low | π° 100 USD
πΉ Weakness: Information Disclosure
πΉ Reported To: Nextcloud
πΉ Reported By: cybershinu90
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:38pm (UTC)
π Source: HackerOne
The vulnerability allowed email enumeration through password-protected share identity verification. Requesting a password for an email share resulted in different response messages depending on whether the email address was the intended recipient, enabling confirmation of the share recipient.
π Read full report
πΉ Severity: Low | π° 100 USD
πΉ Weakness: Information Disclosure
πΉ Reported To: Nextcloud
πΉ Reported By: cybershinu90
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:38pm (UTC)
π Source: HackerOne
The vulnerability allowed email enumeration through password-protected share identity verification. Requesting a password for an email share resulted in different response messages depending on whether the email address was the intended recipient, enabling confirmation of the share recipient.
π Read full report
Unauthenticated testing endpoint of notify_push expose internal IP
πΉ Severity: Medium | π° 150 USD
πΉ Weakness: Information Disclosure
πΉ Reported To: Nextcloud
πΉ Reported By: chinnuy935336
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:45pm (UTC)
π Source: HackerOne
The testing endpoint of the notify_push component exposed internal IP addresses to unauthenticated users.
π Read full report
πΉ Severity: Medium | π° 150 USD
πΉ Weakness: Information Disclosure
πΉ Reported To: Nextcloud
πΉ Reported By: chinnuy935336
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:45pm (UTC)
π Source: HackerOne
The testing endpoint of the notify_push component exposed internal IP addresses to unauthenticated users.
π Read full report
PII Exposure of Credit Applications and Social Security Numbers equifax-6070.my.salesforce-sites.com (Salesforce guest user)
πΉ Severity: High
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Equifax-vdp
πΉ Reported By: dr32
πΉ State: π’ Resolved
πΉ Disclosed: September 6, 2026, 10:03am (UTC)
π Source: HackerOne
A Salesforce community portal belonging to Equifax was found to be leaking tens of thousands of credit reports and other sensitive financial information. The portal's Salesforce guest user profile and sharing settings granted unauthenticated access to multiple objects, including Contact, Online_Credit_Application__c, and related financial data. This exposure allowed an anonymous user to read a large number ofβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Equifax-vdp
πΉ Reported By: dr32
πΉ State: π’ Resolved
πΉ Disclosed: September 6, 2026, 10:03am (UTC)
π Source: HackerOne
A Salesforce community portal belonging to Equifax was found to be leaking tens of thousands of credit reports and other sensitive financial information. The portal's Salesforce guest user profile and sharing settings granted unauthenticated access to multiple objects, including Contact, Online_Credit_Application__c, and related financial data. This exposure allowed an anonymous user to read a large number ofβ¦
π Read full report
ACL cache collision lets a role inherit privileges from a same-named socket user
πΉ Severity: No Rating
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: MariaDB
πΉ Reported By: dogeshark
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:55pm (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB's database privilege cache where a role and a UNIX-socket user with the same name were not distinguished. When the socket user warmed the cache with their privileges, a different account that activated the same-named role then received the cached user privileges, even though those privileges were never granted to the role.
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: MariaDB
πΉ Reported By: dogeshark
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:55pm (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB's database privilege cache where a role and a UNIX-socket user with the same name were not distinguished. When the socket user warmed the cache with their privileges, a different account that activated the same-named role then received the cached user privileges, even though those privileges were never granted to the role.
π Read full report
KILL authorization trusts the presented login name instead of the authenticated anonymous account
πΉ Severity: No Rating
πΉ Weakness: Incorrect Calculation of Buffer Size
πΉ Reported To: MariaDB
πΉ Reported By: dogeshark
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:55pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the KILL authorization process of a database management system. The vulnerability allowed an anonymous account to terminate connections using a supplied login name, even if the authenticated identity was different. This was because the KILL authorization relied on the presented login name instead of the authenticated account identity.
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Incorrect Calculation of Buffer Size
πΉ Reported To: MariaDB
πΉ Reported By: dogeshark
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:55pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the KILL authorization process of a database management system. The vulnerability allowed an anonymous account to terminate connections using a supplied login name, even if the authenticated identity was different. This was because the KILL authorization relied on the presented login name instead of the authenticated account identity.
π Read full report