43: HTTP proxy CONNECT header chooses the `-OJ` filename after a redirect
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
57: Heap out-of-bounds read in `curl_easy_escape_ccsid()` / `curl_easy_unescape_ccsid()`
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
54: Rejected HTTP/2 push destroys MIME callback state still used by parent (use-after-free)
πΉ Severity: No Rating
πΉ Weakness: Use After Free
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Use After Free
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 7, 2026, 9:06pm (UTC)
π Source: HackerOne
π Read full report
HTTP Digest nonce reused across an httpsβhttp scheme change on the same handle
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
Apple SecTrust fallback ignores CURLOPT_CRLFILE, letting a revoked cert pass
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
08: CVE-2026-7009 fix incomplete for AWS-LC: `--cert-status` bypass on SecTrust path
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 6:14am (UTC)
π Source: HackerOne
π Read full report
29: CURLOPT_ISSUERCERT accepts a different-key certificate when issuer metadata collides
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 8:00am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 8:00am (UTC)
π Source: HackerOne
π Read full report
49: Cookie-jar save transfers group access to a different GID
πΉ Severity: No Rating
πΉ Weakness: Improper Preservation of Permissions
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 8:01am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Preservation of Permissions
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 8:01am (UTC)
π Source: HackerOne
π Read full report
Out-of-bounds read in MariaDB .frm parsing enables RCE via vtable hijacking
πΉ Severity: High
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: MariaDB
πΉ Reported By: pinebudweiser
πΉ State: π’ Resolved
πΉ Disclosed: September 8, 2026, 8:19am (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB where the `key_part->fieldnr` value parsed from a crafted `.frm` file was not validated before being used as an index into the `share->field[]` array. This resulted in an out-of-bounds read, allowing an attacker to hijack the C++ virtual method call and achieve arbitrary code execution within the context of the MariaDB server process. The vulnerability was successfullyβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: MariaDB
πΉ Reported By: pinebudweiser
πΉ State: π’ Resolved
πΉ Disclosed: September 8, 2026, 8:19am (UTC)
π Source: HackerOne
A vulnerability was discovered in MariaDB where the `key_part->fieldnr` value parsed from a crafted `.frm` file was not validated before being used as an index into the `share->field[]` array. This resulted in an out-of-bounds read, allowing an attacker to hijack the C++ virtual method call and achieve arbitrary code execution within the context of the MariaDB server process. The vulnerability was successfullyβ¦
π Read full report
Stack Buffer Overflow in mariadb-dump quote_name() Allows Malicious Server to Execute Arbitrary Code on Client
πΉ Severity: Critical
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: byteoverride
πΉ State: π’ Resolved
πΉ Disclosed: September 8, 2026, 1:30pm (UTC)
π Source: HackerOne
A stack buffer overflow was discovered in the quote_name() function of the mariadb-dump client application. The overflow occurred due to a lack of length validation on table names returned by a malicious MySQL server. This allowed a server to provide an excessively long table name that would overflow the fixed-size buffer, leading to the overwriting of the return address and other control-flow data on the stackβ¦
π Read full report
πΉ Severity: Critical
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: byteoverride
πΉ State: π’ Resolved
πΉ Disclosed: September 8, 2026, 1:30pm (UTC)
π Source: HackerOne
A stack buffer overflow was discovered in the quote_name() function of the mariadb-dump client application. The overflow occurred due to a lack of length validation on table names returned by a malicious MySQL server. This allowed a server to provide an excessively long table name that would overflow the fixed-size buffer, leading to the overwriting of the return address and other control-flow data on the stackβ¦
π Read full report
22: FTP wildcard matching decodes server-provided filenames, enabling directory traversal
πΉ Severity: None
πΉ Weakness: Path Traversal
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 2:17pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: None
πΉ Weakness: Path Traversal
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 8, 2026, 2:17pm (UTC)
π Source: HackerOne
π Read full report
Unauthenticated Access to Internal Files via Direct Object Reference (UUID-based) Leading to Sensitive Data Exposure
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Maholi_Tumanggor
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Critical
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Maholi_Tumanggor
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2026
π Source: Bugcrowd
π Read full report
Broken Link Hijacking (Impersonation) on ntrs.nasa.gov via abandoned Facebook URL
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Niranj_R_Mahaswar
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Niranj_R_Mahaswar
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2026
π Source: Bugcrowd
π Read full report
CORS Misconfiguration / Broken Access Control
πΉ Severity: No Rating
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Myndr
πΉ Reported By: shubham71
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 8:16am (UTC)
π Source: HackerOne
A CORS misconfiguration was discovered on the admin panel that allowed any website hosted on a subdomain of the target organization to read authenticated admin responses, including CSRF nonces and session data. This vulnerability could have enabled full admin account takeover through a CSRF attack.
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Myndr
πΉ Reported By: shubham71
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 8:16am (UTC)
π Source: HackerOne
A CORS misconfiguration was discovered on the admin panel that allowed any website hosted on a subdomain of the target organization to read authenticated admin responses, including CSRF nonces and session data. This vulnerability could have enabled full admin account takeover through a CSRF attack.
π Read full report
Tor onion service INTRODUCE2 invalid-MAC cells permanently grow service replay cache
πΉ Severity: Low
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Tor
πΉ Reported By: geeknik
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 12:10pm (UTC)
π Source: HackerOne
A vulnerability was discovered in Tor's onion service INTRODUCE2 handling. A remote client could send well-formed INTRODUCE1 cells with an invalid MAC, but a unique byte pattern. The introduction point would forward these cells as INTRODUCE2 to the onion service. The onion service would insert the attacker-controlled encrypted section into the introduction-point replay cache before verifying the INTRODUCE2 MAC. Theβ¦
π Read full report
πΉ Severity: Low
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Tor
πΉ Reported By: geeknik
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 12:10pm (UTC)
π Source: HackerOne
A vulnerability was discovered in Tor's onion service INTRODUCE2 handling. A remote client could send well-formed INTRODUCE1 cells with an invalid MAC, but a unique byte pattern. The introduction point would forward these cells as INTRODUCE2 to the onion service. The onion service would insert the attacker-controlled encrypted section into the introduction-point replay cache before verifying the INTRODUCE2 MAC. Theβ¦
π Read full report
Conflux-queued zero-length RELAY_END triggers heap out-of-bounds read
πΉ Severity: Medium
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: Tor
πΉ Reported By: geeknik
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 12:10pm (UTC)
π Source: HackerOne
A vulnerability was discovered in Tor that could trigger a heap out-of-bounds read when a zero-length RELAY_END cell was processed on a non-open AP stream. The vulnerability was caused by the way Tor handles these cells, where the reason byte was read before checking the message length. This issue was compounded by Conflux's out-of-order delivery, which could copy the zero-length message into an exact-size heapβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: Tor
πΉ Reported By: geeknik
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 12:10pm (UTC)
π Source: HackerOne
A vulnerability was discovered in Tor that could trigger a heap out-of-bounds read when a zero-length RELAY_END cell was processed on a non-open AP stream. The vulnerability was caused by the way Tor handles these cells, where the reason byte was read before checking the message length. This issue was compounded by Conflux's out-of-order delivery, which could copy the zero-length message into an exact-size heapβ¦
π Read full report
27: IMAP custom FETCH listing classification skips literal boundaries, enabling response desynchronization
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
IMAP connection reuse runs requests in the wrong case-sensitive mailbox
πΉ Severity: Low
πΉ Weakness: Improper Handling of Case Sensitivity
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Weakness: Improper Handling of Case Sensitivity
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
12: SASL DIGEST-MD5 does not validate the server's `rspauth` proof
πΉ Severity: No Rating
πΉ Weakness: Missing Critical Step in Authentication
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Missing Critical Step in Authentication
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
55: Heap-buffer-overflow read in `curl_formadd_ccsid()` with binary form data
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:10pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:10pm (UTC)
π Source: HackerOne
π Read full report
Publicly Accessible Project Documentation Exposes Extensive Project Personnel Contact Information
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: nafee7hh
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: nafee7hh
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026
π Source: Bugcrowd
π Read full report