Broken Link Hijacking (Impersonation) on ntrs.nasa.gov via abandoned Facebook URL
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Niranj_R_Mahaswar
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: Niranj_R_Mahaswar
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2026
π Source: Bugcrowd
π Read full report
CORS Misconfiguration / Broken Access Control
πΉ Severity: No Rating
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Myndr
πΉ Reported By: shubham71
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 8:16am (UTC)
π Source: HackerOne
A CORS misconfiguration was discovered on the admin panel that allowed any website hosted on a subdomain of the target organization to read authenticated admin responses, including CSRF nonces and session data. This vulnerability could have enabled full admin account takeover through a CSRF attack.
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Access Control - Generic
πΉ Reported To: Myndr
πΉ Reported By: shubham71
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 8:16am (UTC)
π Source: HackerOne
A CORS misconfiguration was discovered on the admin panel that allowed any website hosted on a subdomain of the target organization to read authenticated admin responses, including CSRF nonces and session data. This vulnerability could have enabled full admin account takeover through a CSRF attack.
π Read full report
Tor onion service INTRODUCE2 invalid-MAC cells permanently grow service replay cache
πΉ Severity: Low
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Tor
πΉ Reported By: geeknik
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 12:10pm (UTC)
π Source: HackerOne
A vulnerability was discovered in Tor's onion service INTRODUCE2 handling. A remote client could send well-formed INTRODUCE1 cells with an invalid MAC, but a unique byte pattern. The introduction point would forward these cells as INTRODUCE2 to the onion service. The onion service would insert the attacker-controlled encrypted section into the introduction-point replay cache before verifying the INTRODUCE2 MAC. Theβ¦
π Read full report
πΉ Severity: Low
πΉ Weakness: Uncontrolled Resource Consumption
πΉ Reported To: Tor
πΉ Reported By: geeknik
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 12:10pm (UTC)
π Source: HackerOne
A vulnerability was discovered in Tor's onion service INTRODUCE2 handling. A remote client could send well-formed INTRODUCE1 cells with an invalid MAC, but a unique byte pattern. The introduction point would forward these cells as INTRODUCE2 to the onion service. The onion service would insert the attacker-controlled encrypted section into the introduction-point replay cache before verifying the INTRODUCE2 MAC. Theβ¦
π Read full report
Conflux-queued zero-length RELAY_END triggers heap out-of-bounds read
πΉ Severity: Medium
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: Tor
πΉ Reported By: geeknik
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 12:10pm (UTC)
π Source: HackerOne
A vulnerability was discovered in Tor that could trigger a heap out-of-bounds read when a zero-length RELAY_END cell was processed on a non-open AP stream. The vulnerability was caused by the way Tor handles these cells, where the reason byte was read before checking the message length. This issue was compounded by Conflux's out-of-order delivery, which could copy the zero-length message into an exact-size heapβ¦
π Read full report
πΉ Severity: Medium
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: Tor
πΉ Reported By: geeknik
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026, 12:10pm (UTC)
π Source: HackerOne
A vulnerability was discovered in Tor that could trigger a heap out-of-bounds read when a zero-length RELAY_END cell was processed on a non-open AP stream. The vulnerability was caused by the way Tor handles these cells, where the reason byte was read before checking the message length. This issue was compounded by Conflux's out-of-order delivery, which could copy the zero-length message into an exact-size heapβ¦
π Read full report
27: IMAP custom FETCH listing classification skips literal boundaries, enabling response desynchronization
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
IMAP connection reuse runs requests in the wrong case-sensitive mailbox
πΉ Severity: Low
πΉ Weakness: Improper Handling of Case Sensitivity
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Weakness: Improper Handling of Case Sensitivity
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
12: SASL DIGEST-MD5 does not validate the server's `rspauth` proof
πΉ Severity: No Rating
πΉ Weakness: Missing Critical Step in Authentication
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Missing Critical Step in Authentication
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
55: Heap-buffer-overflow read in `curl_formadd_ccsid()` with binary form data
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:10pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:10pm (UTC)
π Source: HackerOne
π Read full report
Publicly Accessible Project Documentation Exposes Extensive Project Personnel Contact Information
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: nafee7hh
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: nafee7hh
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026
π Source: Bugcrowd
π Read full report
Action Text to_markdown: <code>/<pre> content escapes its delimiter, letting a stored body inject arbitrary Markdown
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Ruby on Rails
πΉ Reported By: seoafoz
πΉ State: π’ Resolved
πΉ Disclosed: September 12, 2026, 7:08pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Ruby on Rails
πΉ Reported By: seoafoz
πΉ State: π’ Resolved
πΉ Disclosed: September 12, 2026, 7:08pm (UTC)
π Source: HackerOne
π Read full report
HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers
πΉ Severity: High | π° 1,500 USD
πΉ Weakness: HTTP Request Smuggling
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: 1nsomnia1102
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026, 4:57am (UTC)
π Source: HackerOne
A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.
π Read full report
πΉ Severity: High | π° 1,500 USD
πΉ Weakness: HTTP Request Smuggling
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: 1nsomnia1102
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026, 4:57am (UTC)
π Source: HackerOne
A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.
π Read full report
[Atlas Browser] Fullscreen notification is missing when requestFullscreen() is called from a popup window
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
[Atlas Browser] Fullscreen Notification Overlap by Screen Share Permission Dialog Leading to UI Spoofing and Unauthorized Screen Capture in ChatGPT Atlas for macOS
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
37: `curl_mprintf` `%F` format specifier not consumed, causing variadic argument desynchronization
πΉ Severity: No Rating
πΉ Weakness: Type Confusion
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Type Confusion
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
10: CURLOPT_MAXLIFETIME_CONN bypass on active HTTP/2 connections
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
56: IBM i CL wrapper `parse_command_line()` never enters quote mode
πΉ Severity: No Rating
πΉ Weakness: Command Injection - Generic
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Command Injection - Generic
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
53: HTTP/1 CONNECT chunked-407 trailers bypass CURLOPT_SUPPRESS_CONNECT_HEADERS and lose CURLH_CONNECT classification
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
Heap-use-after-free in CURLOPT_REFERER when passed a CURLINFO_REFERER pointer
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:59am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:59am (UTC)
π Source: HackerOne
π Read full report