12: SASL DIGEST-MD5 does not validate the server's `rspauth` proof
πΉ Severity: No Rating
πΉ Weakness: Missing Critical Step in Authentication
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Missing Critical Step in Authentication
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:09pm (UTC)
π Source: HackerOne
π Read full report
55: Heap-buffer-overflow read in `curl_formadd_ccsid()` with binary form data
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:10pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Out-of-bounds Read
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 10, 2026, 3:10pm (UTC)
π Source: HackerOne
π Read full report
Publicly Accessible Project Documentation Exposes Extensive Project Personnel Contact Information
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: nafee7hh
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Informational
πΉ Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
πΉ Reported By: nafee7hh
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2026
π Source: Bugcrowd
π Read full report
Action Text to_markdown: <code>/<pre> content escapes its delimiter, letting a stored body inject arbitrary Markdown
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Ruby on Rails
πΉ Reported By: seoafoz
πΉ State: π’ Resolved
πΉ Disclosed: September 12, 2026, 7:08pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Cross-site Scripting (XSS) - Stored
πΉ Reported To: Ruby on Rails
πΉ Reported By: seoafoz
πΉ State: π’ Resolved
πΉ Disclosed: September 12, 2026, 7:08pm (UTC)
π Source: HackerOne
π Read full report
HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers
πΉ Severity: High | π° 1,500 USD
πΉ Weakness: HTTP Request Smuggling
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: 1nsomnia1102
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026, 4:57am (UTC)
π Source: HackerOne
A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.
π Read full report
πΉ Severity: High | π° 1,500 USD
πΉ Weakness: HTTP Request Smuggling
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: 1nsomnia1102
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026, 4:57am (UTC)
π Source: HackerOne
A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.
π Read full report
[Atlas Browser] Fullscreen notification is missing when requestFullscreen() is called from a popup window
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
[Atlas Browser] Fullscreen Notification Overlap by Screen Share Permission Dialog Leading to UI Spoofing and Unauthorized Screen Capture in ChatGPT Atlas for macOS
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
37: `curl_mprintf` `%F` format specifier not consumed, causing variadic argument desynchronization
πΉ Severity: No Rating
πΉ Weakness: Type Confusion
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Type Confusion
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
10: CURLOPT_MAXLIFETIME_CONN bypass on active HTTP/2 connections
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Improper Certificate Validation
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
56: IBM i CL wrapper `parse_command_line()` never enters quote mode
πΉ Severity: No Rating
πΉ Weakness: Command Injection - Generic
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Command Injection - Generic
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
53: HTTP/1 CONNECT chunked-407 trailers bypass CURLOPT_SUPPRESS_CONNECT_HEADERS and lose CURLH_CONNECT classification
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: No Rating
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:58am (UTC)
π Source: HackerOne
π Read full report
Heap-use-after-free in CURLOPT_REFERER when passed a CURLINFO_REFERER pointer
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:59am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:59am (UTC)
π Source: HackerOne
π Read full report
OpenSSL ENGINE selection omitted from mTLS connection matching
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:59am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:59am (UTC)
π Source: HackerOne
π Read full report
TLS session resumption client cert bypass with CURLOPT_SSL_CTX_FUNCTION
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: causalsecurity
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 7:41am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: causalsecurity
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 7:41am (UTC)
π Source: HackerOne
π Read full report
[Atlas Browser]Bypass the full-screen notification security layer by displaying a permission dialog to open an external app
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
[Atlas Browser]Bypassing Full-Screen Notification via Right-Click Context Menu Leads to Spoofing Attacks
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
Use-After-Free in BTREE Index Traversal via Stale key_version in heap_update() in MariaDB Server
πΉ Severity: No Rating
πΉ Weakness: Use After Free
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026, 4:05pm (UTC)
π Source: HackerOne
A use-after-free vulnerability was discovered in the MEMORY (HEAP) storage engine of MariaDB Server. The vulnerability was caused by incorrect handling of the `key_changed` variable in the `heap_update()` function, which could lead to stale pointers being dereferenced during BTREE index traversal. While the vulnerability could be triggered by an authenticated user with standard database privileges, no furtherβ¦
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Use After Free
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026, 4:05pm (UTC)
π Source: HackerOne
A use-after-free vulnerability was discovered in the MEMORY (HEAP) storage engine of MariaDB Server. The vulnerability was caused by incorrect handling of the `key_changed` variable in the `heap_update()` function, which could lead to stale pointers being dereferenced during BTREE index traversal. While the vulnerability could be triggered by an authenticated user with standard database privileges, no furtherβ¦
π Read full report