Bugpoint
970 subscribers
3.93K photos
3.93K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
27: IMAP custom FETCH listing classification skips literal boundaries, enabling response desynchronization

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 10, 2026, 3:09pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
IMAP connection reuse runs requests in the wrong case-sensitive mailbox

πŸ”Ή Severity: Low
πŸ”Ή Weakness: Improper Handling of Case Sensitivity
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 10, 2026, 3:09pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
12: SASL DIGEST-MD5 does not validate the server's `rspauth` proof

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Missing Critical Step in Authentication
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 10, 2026, 3:09pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
55: Heap-buffer-overflow read in `curl_formadd_ccsid()` with binary form data

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Out-of-bounds Read
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 10, 2026, 3:10pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Publicly Accessible Project Documentation Exposes Extensive Project Personnel Contact Information

πŸ”Ή Severity: Informational
πŸ”Ή Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πŸ”Ή Reported By: nafee7hh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 10, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Action Text to_markdown: <code>/<pre> content escapes its delimiter, letting a stored body inject arbitrary Markdown

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Cross-site Scripting (XSS) - Stored
πŸ”Ή Reported To: Ruby on Rails
πŸ”Ή Reported By: seoafoz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 12, 2026, 7:08pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers

πŸ”Ή Severity: High | πŸ’° 1,500 USD
πŸ”Ή Weakness: HTTP Request Smuggling
πŸ”Ή Reported To: Cloudflare Public Bug Bounty
πŸ”Ή Reported By: 1nsomnia1102
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026, 4:57am (UTC)
🐞 Source: HackerOne

A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.

πŸ‘‰ Read full report
[Atlas Browser] Fullscreen notification is missing when requestFullscreen() is called from a popup window

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
[Atlas Browser] Fullscreen Notification Overlap by Screen Share Permission Dialog Leading to UI Spoofing and Unauthorized Screen Capture in ChatGPT Atlas for macOS

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
37: `curl_mprintf` `%F` format specifier not consumed, causing variadic argument desynchronization

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Type Confusion
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
10: CURLOPT_MAXLIFETIME_CONN bypass on active HTTP/2 connections

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
56: IBM i CL wrapper `parse_command_line()` never enters quote mode

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Command Injection - Generic
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
53: HTTP/1 CONNECT chunked-407 trailers bypass CURLOPT_SUPPRESS_CONNECT_HEADERS and lose CURLH_CONNECT classification

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Heap-use-after-free in CURLOPT_REFERER when passed a CURLINFO_REFERER pointer

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:59am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
OpenSSL ENGINE selection omitted from mTLS connection matching

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:59am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
TLS session resumption client cert bypass with CURLOPT_SSL_CTX_FUNCTION

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Authentication Bypass by Primary Weakness
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: causalsecurity
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 7:41am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
[Atlas Browser]Bypass the full-screen notification security layer by displaying a permission dialog to open an external app

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
[Atlas Browser]Bypassing Full-Screen Notification via Right-Click Context Menu Leads to Spoofing Attacks

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Use-After-Free in BTREE Index Traversal via Stale key_version in heap_update() in MariaDB Server

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Use After Free
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: lukas_kupczyk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026, 4:05pm (UTC)
🐞 Source: HackerOne

A use-after-free vulnerability was discovered in the MEMORY (HEAP) storage engine of MariaDB Server. The vulnerability was caused by incorrect handling of the `key_changed` variable in the `heap_update()` function, which could lead to stale pointers being dereferenced during BTREE index traversal. While the vulnerability could be triggered by an authenticated user with standard database privileges, no further…

πŸ‘‰ Read full report