Improper Input Validation and Integer Overflow in timeamount parameter of files_retention app
πΉ Severity: Low
πΉ Weakness: Integer Overflow
πΉ Reported To: Nextcloud
πΉ Reported By: nishantbaswal1996
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:29pm (UTC)
π Source: HackerOne
The timeamount parameter of the files_retention app lacked proper input validation, allowing an administrator to store an unintended long time amount as the retention period. This vulnerability could have potentially led to files never getting deleted.
π Read full report
πΉ Severity: Low
πΉ Weakness: Integer Overflow
πΉ Reported To: Nextcloud
πΉ Reported By: nishantbaswal1996
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:29pm (UTC)
π Source: HackerOne
The timeamount parameter of the files_retention app lacked proper input validation, allowing an administrator to store an unintended long time amount as the retention period. This vulnerability could have potentially led to files never getting deleted.
π Read full report
Email Enumeration via Password-Protected Share Identity Verification
πΉ Severity: Low | π° 100 USD
πΉ Weakness: Information Disclosure
πΉ Reported To: Nextcloud
πΉ Reported By: cybershinu90
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:38pm (UTC)
π Source: HackerOne
The vulnerability allowed email enumeration through password-protected share identity verification. Requesting a password for an email share resulted in different response messages depending on whether the email address was the intended recipient, enabling confirmation of the share recipient.
π Read full report
πΉ Severity: Low | π° 100 USD
πΉ Weakness: Information Disclosure
πΉ Reported To: Nextcloud
πΉ Reported By: cybershinu90
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:38pm (UTC)
π Source: HackerOne
The vulnerability allowed email enumeration through password-protected share identity verification. Requesting a password for an email share resulted in different response messages depending on whether the email address was the intended recipient, enabling confirmation of the share recipient.
π Read full report
Unauthenticated testing endpoint of notify_push expose internal IP
πΉ Severity: Medium | π° 150 USD
πΉ Weakness: Information Disclosure
πΉ Reported To: Nextcloud
πΉ Reported By: chinnuy935336
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:45pm (UTC)
π Source: HackerOne
The testing endpoint of the notify_push component exposed internal IP addresses to unauthenticated users.
π Read full report
πΉ Severity: Medium | π° 150 USD
πΉ Weakness: Information Disclosure
πΉ Reported To: Nextcloud
πΉ Reported By: chinnuy935336
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2026, 2:45pm (UTC)
π Source: HackerOne
The testing endpoint of the notify_push component exposed internal IP addresses to unauthenticated users.
π Read full report
PII Exposure of Credit Applications and Social Security Numbers equifax-6070.my.salesforce-sites.com (Salesforce guest user)
πΉ Severity: High
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Equifax-vdp
πΉ Reported By: dr32
πΉ State: π’ Resolved
πΉ Disclosed: September 6, 2026, 10:03am (UTC)
π Source: HackerOne
A Salesforce community portal belonging to Equifax was found to be leaking tens of thousands of credit reports and other sensitive financial information. The portal's Salesforce guest user profile and sharing settings granted unauthenticated access to multiple objects, including Contact, Online_Credit_Application__c, and related financial data. This exposure allowed an anonymous user to read a large number ofβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: Equifax-vdp
πΉ Reported By: dr32
πΉ State: π’ Resolved
πΉ Disclosed: September 6, 2026, 10:03am (UTC)
π Source: HackerOne
A Salesforce community portal belonging to Equifax was found to be leaking tens of thousands of credit reports and other sensitive financial information. The portal's Salesforce guest user profile and sharing settings granted unauthenticated access to multiple objects, including Contact, Online_Credit_Application__c, and related financial data. This exposure allowed an anonymous user to read a large number ofβ¦
π Read full report
ACL cache collision lets a role inherit privileges from a same-named socket user
πΉ Severity: No Rating
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: MariaDB
πΉ Reported By: dogeshark
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:55pm (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB's database privilege cache where a role and a UNIX-socket user with the same name were not distinguished. When the socket user warmed the cache with their privileges, a different account that activated the same-named role then received the cached user privileges, even though those privileges were never granted to the role.
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Authentication - Generic
πΉ Reported To: MariaDB
πΉ Reported By: dogeshark
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:55pm (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB's database privilege cache where a role and a UNIX-socket user with the same name were not distinguished. When the socket user warmed the cache with their privileges, a different account that activated the same-named role then received the cached user privileges, even though those privileges were never granted to the role.
π Read full report
KILL authorization trusts the presented login name instead of the authenticated anonymous account
πΉ Severity: No Rating
πΉ Weakness: Incorrect Calculation of Buffer Size
πΉ Reported To: MariaDB
πΉ Reported By: dogeshark
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:55pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the KILL authorization process of a database management system. The vulnerability allowed an anonymous account to terminate connections using a supplied login name, even if the authenticated identity was different. This was because the KILL authorization relied on the presented login name instead of the authenticated account identity.
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Incorrect Calculation of Buffer Size
πΉ Reported To: MariaDB
πΉ Reported By: dogeshark
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:55pm (UTC)
π Source: HackerOne
A vulnerability was discovered in the KILL authorization process of a database management system. The vulnerability allowed an anonymous account to terminate connections using a supplied login name, even if the authenticated identity was different. This was because the KILL authorization relied on the presented login name instead of the authenticated account identity.
π Read full report
MariaDB: heap buffer overflow in ha_tina::chain_append() lets a low-privileged user crash the server via CSV row deletion
πΉ Severity: Medium
πΉ Weakness: Heap Overflow
πΉ Reported To: MariaDB
πΉ Reported By: v3rtical
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:59pm (UTC)
π Source: HackerOne
A heap buffer overflow vulnerability was discovered in the ha_tina::chain_append() function of the MariaDB database server. The vulnerability was caused by an incorrect memory allocation during the growth of a data structure. This could allow a low-privileged user to crash the server by executing a specific SQL command involving CSV data deletion. The vulnerability was confirmed to affect both the stock Ubuntuβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Heap Overflow
πΉ Reported To: MariaDB
πΉ Reported By: v3rtical
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 7:59pm (UTC)
π Source: HackerOne
A heap buffer overflow vulnerability was discovered in the ha_tina::chain_append() function of the MariaDB database server. The vulnerability was caused by an incorrect memory allocation during the growth of a data structure. This could allow a low-privileged user to crash the server by executing a specific SQL command involving CSV data deletion. The vulnerability was confirmed to affect both the stock Ubuntuβ¦
π Read full report
MariaDB GRANT PROXY permits unauthorized authentication changes and administrator account takeover
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: MariaDB
πΉ Reported By: kevin_mizu
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 8:07pm (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB that allowed an authenticated user with only USAGE privileges to change the password of an existing administrator account. This was achieved through the grantee clause of the GRANT PROXY statement, which permitted bypassing the authorization checks and directly modifying the target account's authentication information. The vulnerability was tested on MariaDB versions 12.3.2β¦
π Read full report
πΉ Severity: High
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: MariaDB
πΉ Reported By: kevin_mizu
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2026, 8:07pm (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB that allowed an authenticated user with only USAGE privileges to change the password of an existing administrator account. This was achieved through the grantee clause of the GRANT PROXY statement, which permitted bypassing the authorization checks and directly modifying the target account's authentication information. The vulnerability was tested on MariaDB versions 12.3.2β¦
π Read full report
11: `CURLOPT_FORBID_REUSE` silently lost on multiplexed HTTP/2 connection when the forbidding transfer finishes first
πΉ Severity: No Rating
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:05pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:05pm (UTC)
π Source: HackerOne
π Read full report
36: HTTP upload resume offset consumed twice after early 307/308 redirect
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
43: HTTP proxy CONNECT header chooses the `-OJ` filename after a redirect
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
57: Heap out-of-bounds read in `curl_easy_escape_ccsid()` / `curl_easy_unescape_ccsid()`
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
54: Rejected HTTP/2 push destroys MIME callback state still used by parent (use-after-free)
πΉ Severity: No Rating
πΉ Weakness: Use After Free
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Use After Free
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
HTTP Digest nonce reused across an httpsβhttp scheme change on the same handle
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
Apple SecTrust fallback ignores CURLOPT_CRLFILE, letting a revoked cert pass
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
08: CVE-2026-7009 fix incomplete for AWS-LC: `--cert-status` bypass on SecTrust path
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
29: CURLOPT_ISSUERCERT accepts a different-key certificate when issuer metadata collides
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 8:00am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 8:00am (UTC)
π Source: HackerOne
π Read full report
49: Cookie-jar save transfers group access to a different GID
πΉ Severity: No Rating
πΉ Weakness: Improper Preservation of Permissions
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 8:01am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Preservation of Permissions
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 8:01am (UTC)
π Source: HackerOne
π Read full report
Out-of-bounds read in MariaDB .frm parsing enables RCE via vtable hijacking
πΉ Severity: High
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: MariaDB
πΉ Reported By: pinebudweiser
πΉ State: π’ Resolved
πΉ Disclosed: September 8, 2026, 8:19am (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB where the `key_part->fieldnr` value parsed from a crafted `.frm` file was not validated before being used as an index into the `share->field[]` array. This resulted in an out-of-bounds read, allowing an attacker to hijack the C++ virtual method call and achieve arbitrary code execution within the context of the MariaDB server process. The vulnerability was successfullyβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: MariaDB
πΉ Reported By: pinebudweiser
πΉ State: π’ Resolved
πΉ Disclosed: September 8, 2026, 8:19am (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB where the `key_part->fieldnr` value parsed from a crafted `.frm` file was not validated before being used as an index into the `share->field[]` array. This resulted in an out-of-bounds read, allowing an attacker to hijack the C++ virtual method call and achieve arbitrary code execution within the context of the MariaDB server process. The vulnerability was successfullyβ¦
π Read full report
Stack Buffer Overflow in mariadb-dump quote_name() Allows Malicious Server to Execute Arbitrary Code on Client
πΉ Severity: Critical
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: byteoverride
πΉ State: π’ Resolved
πΉ Disclosed: September 8, 2026, 1:30pm (UTC)
π Source: HackerOne
A stack buffer overflow was discovered in the quote_name() function of the mariadb-dump client application. The overflow occurred due to a lack of length validation on table names returned by a malicious MySQL server. This allowed a server to provide an excessively long table name that would overflow the fixed-size buffer, leading to the overwriting of the return address and other control-flow data on the stackβ¦
π Read full report
πΉ Severity: Critical
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: byteoverride
πΉ State: π’ Resolved
πΉ Disclosed: September 8, 2026, 1:30pm (UTC)
π Source: HackerOne
A stack buffer overflow was discovered in the quote_name() function of the mariadb-dump client application. The overflow occurred due to a lack of length validation on table names returned by a malicious MySQL server. This allowed a server to provide an excessively long table name that would overflow the fixed-size buffer, leading to the overwriting of the return address and other control-flow data on the stackβ¦
π Read full report
22: FTP wildcard matching decodes server-provided filenames, enabling directory traversal
πΉ Severity: None
πΉ Weakness: Path Traversal
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 2:17pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: None
πΉ Weakness: Path Traversal
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 2:17pm (UTC)
π Source: HackerOne
π Read full report