Bugpoint
970 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
MariaDB: heap buffer overflow in ha_tina::chain_append() lets a low-privileged user crash the server via CSV row deletion

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Heap Overflow
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: v3rtical
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 7, 2026, 7:59pm (UTC)
🐞 Source: HackerOne

A heap buffer overflow vulnerability was discovered in the ha_tina::chain_append() function of the MariaDB database server. The vulnerability was caused by an incorrect memory allocation during the growth of a data structure. This could allow a low-privileged user to crash the server by executing a specific SQL command involving CSV data deletion. The vulnerability was confirmed to affect both the stock Ubuntu…

πŸ‘‰ Read full report
MariaDB GRANT PROXY permits unauthorized authentication changes and administrator account takeover

πŸ”Ή Severity: High
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: kevin_mizu
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 7, 2026, 8:07pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in MariaDB that allowed an authenticated user with only USAGE privileges to change the password of an existing administrator account. This was achieved through the grantee clause of the GRANT PROXY statement, which permitted bypassing the authorization checks and directly modifying the target account's authentication information. The vulnerability was tested on MariaDB versions 12.3.2…

πŸ‘‰ Read full report
11: `CURLOPT_FORBID_REUSE` silently lost on multiplexed HTTP/2 connection when the forbidding transfer finishes first

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Authentication Bypass by Primary Weakness
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:05pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
36: HTTP upload resume offset consumed twice after early 307/308 redirect

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:06pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
43: HTTP proxy CONNECT header chooses the `-OJ` filename after a redirect

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:06pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
57: Heap out-of-bounds read in `curl_easy_escape_ccsid()` / `curl_easy_unescape_ccsid()`

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Out-of-bounds Read
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:06pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
54: Rejected HTTP/2 push destroys MIME callback state still used by parent (use-after-free)

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Use After Free
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 7, 2026, 9:06pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
HTTP Digest nonce reused across an https→http scheme change on the same handle

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 6:14am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Apple SecTrust fallback ignores CURLOPT_CRLFILE, letting a revoked cert pass

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 6:14am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
08: CVE-2026-7009 fix incomplete for AWS-LC: `--cert-status` bypass on SecTrust path

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 6:14am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
29: CURLOPT_ISSUERCERT accepts a different-key certificate when issuer metadata collides

πŸ”Ή Severity: None
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 8:00am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
49: Cookie-jar save transfers group access to a different GID

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Preservation of Permissions
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 8:01am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Out-of-bounds read in MariaDB .frm parsing enables RCE via vtable hijacking

πŸ”Ή Severity: High
πŸ”Ή Weakness: Out-of-bounds Read
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: pinebudweiser
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2026, 8:19am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in MariaDB where the `key_part->fieldnr` value parsed from a crafted `.frm` file was not validated before being used as an index into the `share->field[]` array. This resulted in an out-of-bounds read, allowing an attacker to hijack the C++ virtual method call and achieve arbitrary code execution within the context of the MariaDB server process. The vulnerability was successfully…

πŸ‘‰ Read full report
Stack Buffer Overflow in mariadb-dump quote_name() Allows Malicious Server to Execute Arbitrary Code on Client

πŸ”Ή Severity: Critical
πŸ”Ή Weakness: Stack Overflow
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: byteoverride
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 8, 2026, 1:30pm (UTC)
🐞 Source: HackerOne

A stack buffer overflow was discovered in the quote_name() function of the mariadb-dump client application. The overflow occurred due to a lack of length validation on table names returned by a malicious MySQL server. This allowed a server to provide an excessively long table name that would overflow the fixed-size buffer, leading to the overwriting of the return address and other control-flow data on the stack…

πŸ‘‰ Read full report
22: FTP wildcard matching decodes server-provided filenames, enabling directory traversal

πŸ”Ή Severity: None
πŸ”Ή Weakness: Path Traversal
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 8, 2026, 2:17pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Unauthenticated Access to Internal Files via Direct Object Reference (UUID-based) Leading to Sensitive Data Exposure

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: Maholi_Tumanggor
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 9, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Broken Link Hijacking (Impersonation) on ntrs.nasa.gov via abandoned Facebook URL

πŸ”Ή Severity: Low
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: Niranj_R_Mahaswar
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 9, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
CORS Misconfiguration / Broken Access Control

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Myndr
πŸ”Ή Reported By: shubham71
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2026, 8:16am (UTC)
🐞 Source: HackerOne

A CORS misconfiguration was discovered on the admin panel that allowed any website hosted on a subdomain of the target organization to read authenticated admin responses, including CSRF nonces and session data. This vulnerability could have enabled full admin account takeover through a CSRF attack.

πŸ‘‰ Read full report
Tor onion service INTRODUCE2 invalid-MAC cells permanently grow service replay cache

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Uncontrolled Resource Consumption
πŸ”Ή Reported To: Tor
πŸ”Ή Reported By: geeknik
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2026, 12:10pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Tor's onion service INTRODUCE2 handling. A remote client could send well-formed INTRODUCE1 cells with an invalid MAC, but a unique byte pattern. The introduction point would forward these cells as INTRODUCE2 to the onion service. The onion service would insert the attacker-controlled encrypted section into the introduction-point replay cache before verifying the INTRODUCE2 MAC. The…

πŸ‘‰ Read full report
Conflux-queued zero-length RELAY_END triggers heap out-of-bounds read

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Out-of-bounds Read
πŸ”Ή Reported To: Tor
πŸ”Ή Reported By: geeknik
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2026, 12:10pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Tor that could trigger a heap out-of-bounds read when a zero-length RELAY_END cell was processed on a non-open AP stream. The vulnerability was caused by the way Tor handles these cells, where the reason byte was read before checking the message length. This issue was compounded by Conflux's out-of-order delivery, which could copy the zero-length message into an exact-size heap…

πŸ‘‰ Read full report
27: IMAP custom FETCH listing classification skips literal boundaries, enabling response desynchronization

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 10, 2026, 3:09pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report