Bugpoint
970 subscribers
3.92K photos
3.93K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Tor onion service INTRODUCE2 invalid-MAC cells permanently grow service replay cache

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Uncontrolled Resource Consumption
πŸ”Ή Reported To: Tor
πŸ”Ή Reported By: geeknik
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2026, 12:10pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Tor's onion service INTRODUCE2 handling. A remote client could send well-formed INTRODUCE1 cells with an invalid MAC, but a unique byte pattern. The introduction point would forward these cells as INTRODUCE2 to the onion service. The onion service would insert the attacker-controlled encrypted section into the introduction-point replay cache before verifying the INTRODUCE2 MAC. The…

πŸ‘‰ Read full report
Conflux-queued zero-length RELAY_END triggers heap out-of-bounds read

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Out-of-bounds Read
πŸ”Ή Reported To: Tor
πŸ”Ή Reported By: geeknik
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2026, 12:10pm (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Tor that could trigger a heap out-of-bounds read when a zero-length RELAY_END cell was processed on a non-open AP stream. The vulnerability was caused by the way Tor handles these cells, where the reason byte was read before checking the message length. This issue was compounded by Conflux's out-of-order delivery, which could copy the zero-length message into an exact-size heap…

πŸ‘‰ Read full report
27: IMAP custom FETCH listing classification skips literal boundaries, enabling response desynchronization

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 10, 2026, 3:09pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
IMAP connection reuse runs requests in the wrong case-sensitive mailbox

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Improper Handling of Case Sensitivity
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 10, 2026, 3:09pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
12: SASL DIGEST-MD5 does not validate the server's `rspauth` proof

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Missing Critical Step in Authentication
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 10, 2026, 3:09pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
55: Heap-buffer-overflow read in `curl_formadd_ccsid()` with binary form data

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Out-of-bounds Read
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 10, 2026, 3:10pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Publicly Accessible Project Documentation Exposes Extensive Project Personnel Contact Information

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: nafee7hh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Action Text to_markdown: <code>/<pre> content escapes its delimiter, letting a stored body inject arbitrary Markdown

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: Ruby on Rails
πŸ”Ή Reported By: seoafoz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 12, 2026, 7:08pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers

πŸ”Ή Severity: High | πŸ’° 1,500 USD
πŸ”Ή Weakness: HTTP Request Smuggling
πŸ”Ή Reported To: Cloudflare Public Bug Bounty
πŸ”Ή Reported By: 1nsomnia1102
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026, 4:57am (UTC)
🐞 Source: HackerOne

A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.

πŸ‘‰ Read full report
[Atlas Browser] Fullscreen notification is missing when requestFullscreen() is called from a popup window

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
[Atlas Browser] Fullscreen Notification Overlap by Screen Share Permission Dialog Leading to UI Spoofing and Unauthorized Screen Capture in ChatGPT Atlas for macOS

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
37: `curl_mprintf` `%F` format specifier not consumed, causing variadic argument desynchronization

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Type Confusion
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
10: CURLOPT_MAXLIFETIME_CONN bypass on active HTTP/2 connections

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
56: IBM i CL wrapper `parse_command_line()` never enters quote mode

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Command Injection - Generic
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
53: HTTP/1 CONNECT chunked-407 trailers bypass CURLOPT_SUPPRESS_CONNECT_HEADERS and lose CURLH_CONNECT classification

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Heap-use-after-free in CURLOPT_REFERER when passed a CURLINFO_REFERER pointer

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:59am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report