Bugpoint
970 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Improper Input Validation and Integer Overflow in timeamount parameter of files_retention app

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Integer Overflow
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: nishantbaswal1996
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2026, 2:29pm (UTC)
🐞 Source: HackerOne

The timeamount parameter of the files_retention app lacked proper input validation, allowing an administrator to store an unintended long time amount as the retention period. This vulnerability could have potentially led to files never getting deleted.

πŸ‘‰ Read full report
Email Enumeration via Password-Protected Share Identity Verification

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: cybershinu90
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2026, 2:38pm (UTC)
🐞 Source: HackerOne

The vulnerability allowed email enumeration through password-protected share identity verification. Requesting a password for an email share resulted in different response messages depending on whether the email address was the intended recipient, enabling confirmation of the share recipient.

πŸ‘‰ Read full report
Unauthenticated testing endpoint of notify_push expose internal IP

πŸ”Ή Severity: Medium | πŸ’° 150 USD
πŸ”Ή Weakness: Information Disclosure
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: chinnuy935336
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 5, 2026, 2:45pm (UTC)
🐞 Source: HackerOne

The testing endpoint of the notify_push component exposed internal IP addresses to unauthenticated users.

πŸ‘‰ Read full report
PII Exposure of Credit Applications and Social Security Numbers equifax-6070.my.salesforce-sites.com (Salesforce guest user)

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Authentication - Generic
πŸ”Ή Reported To: Equifax-vdp
πŸ”Ή Reported By: dr32
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 6, 2026, 10:03am (UTC)
🐞 Source: HackerOne

A Salesforce community portal belonging to Equifax was found to be leaking tens of thousands of credit reports and other sensitive financial information. The portal's Salesforce guest user profile and sharing settings granted unauthenticated access to multiple objects, including Contact, Online_Credit_Application__c, and related financial data. This exposure allowed an anonymous user to read a large number of…

πŸ‘‰ Read full report
ACL cache collision lets a role inherit privileges from a same-named socket user

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Authentication - Generic
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: dogeshark
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 7, 2026, 7:55pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in MariaDB's database privilege cache where a role and a UNIX-socket user with the same name were not distinguished. When the socket user warmed the cache with their privileges, a different account that activated the same-named role then received the cached user privileges, even though those privileges were never granted to the role.

πŸ‘‰ Read full report
KILL authorization trusts the presented login name instead of the authenticated anonymous account

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Incorrect Calculation of Buffer Size
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: dogeshark
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 7, 2026, 7:55pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the KILL authorization process of a database management system. The vulnerability allowed an anonymous account to terminate connections using a supplied login name, even if the authenticated identity was different. This was because the KILL authorization relied on the presented login name instead of the authenticated account identity.

πŸ‘‰ Read full report
MariaDB: heap buffer overflow in ha_tina::chain_append() lets a low-privileged user crash the server via CSV row deletion

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Heap Overflow
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: v3rtical
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 7, 2026, 7:59pm (UTC)
🐞 Source: HackerOne

A heap buffer overflow vulnerability was discovered in the ha_tina::chain_append() function of the MariaDB database server. The vulnerability was caused by an incorrect memory allocation during the growth of a data structure. This could allow a low-privileged user to crash the server by executing a specific SQL command involving CSV data deletion. The vulnerability was confirmed to affect both the stock Ubuntu…

πŸ‘‰ Read full report
MariaDB GRANT PROXY permits unauthorized authentication changes and administrator account takeover

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: kevin_mizu
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 7, 2026, 8:07pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in MariaDB that allowed an authenticated user with only USAGE privileges to change the password of an existing administrator account. This was achieved through the grantee clause of the GRANT PROXY statement, which permitted bypassing the authorization checks and directly modifying the target account's authentication information. The vulnerability was tested on MariaDB versions 12.3.2…

πŸ‘‰ Read full report
11: `CURLOPT_FORBID_REUSE` silently lost on multiplexed HTTP/2 connection when the forbidding transfer finishes first

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Authentication Bypass by Primary Weakness
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:05pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
36: HTTP upload resume offset consumed twice after early 307/308 redirect

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:06pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
43: HTTP proxy CONNECT header chooses the `-OJ` filename after a redirect

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:06pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
57: Heap out-of-bounds read in `curl_easy_escape_ccsid()` / `curl_easy_unescape_ccsid()`

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Out-of-bounds Read
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:06pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
54: Rejected HTTP/2 push destroys MIME callback state still used by parent (use-after-free)

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Use After Free
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:06pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
HTTP Digest nonce reused across an https→http scheme change on the same handle

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 6:14am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Apple SecTrust fallback ignores CURLOPT_CRLFILE, letting a revoked cert pass

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 6:14am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
08: CVE-2026-7009 fix incomplete for AWS-LC: `--cert-status` bypass on SecTrust path

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 6:14am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
29: CURLOPT_ISSUERCERT accepts a different-key certificate when issuer metadata collides

πŸ”Ή Severity: None
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 8:00am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
49: Cookie-jar save transfers group access to a different GID

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Preservation of Permissions
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 8:01am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Out-of-bounds read in MariaDB .frm parsing enables RCE via vtable hijacking

πŸ”Ή Severity: High
πŸ”Ή Weakness: Out-of-bounds Read
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: pinebudweiser
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2026, 8:19am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in MariaDB where the `key_part->fieldnr` value parsed from a crafted `.frm` file was not validated before being used as an index into the `share->field[]` array. This resulted in an out-of-bounds read, allowing an attacker to hijack the C++ virtual method call and achieve arbitrary code execution within the context of the MariaDB server process. The vulnerability was successfully…

πŸ‘‰ Read full report
Stack Buffer Overflow in mariadb-dump quote_name() Allows Malicious Server to Execute Arbitrary Code on Client

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Stack Overflow
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: byteoverride
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2026, 1:30pm (UTC)
🐞 Source: HackerOne

A stack buffer overflow was discovered in the quote_name() function of the mariadb-dump client application. The overflow occurred due to a lack of length validation on table names returned by a malicious MySQL server. This allowed a server to provide an excessively long table name that would overflow the fixed-size buffer, leading to the overwriting of the return address and other control-flow data on the stack…

πŸ‘‰ Read full report
22: FTP wildcard matching decodes server-provided filenames, enabling directory traversal

πŸ”Ή Severity: None
πŸ”Ή Weakness: Path Traversal
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 2:17pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report