Bugpoint
970 subscribers
3.93K photos
3.93K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers

πŸ”Ή Severity: High | πŸ’° 1,500 USD
πŸ”Ή Weakness: HTTP Request Smuggling
πŸ”Ή Reported To: Cloudflare Public Bug Bounty
πŸ”Ή Reported By: 1nsomnia1102
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026, 4:57am (UTC)
🐞 Source: HackerOne

A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.

πŸ‘‰ Read full report
[Atlas Browser] Fullscreen notification is missing when requestFullscreen() is called from a popup window

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
[Atlas Browser] Fullscreen Notification Overlap by Screen Share Permission Dialog Leading to UI Spoofing and Unauthorized Screen Capture in ChatGPT Atlas for macOS

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
37: `curl_mprintf` `%F` format specifier not consumed, causing variadic argument desynchronization

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Type Confusion
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
10: CURLOPT_MAXLIFETIME_CONN bypass on active HTTP/2 connections

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
56: IBM i CL wrapper `parse_command_line()` never enters quote mode

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Command Injection - Generic
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
53: HTTP/1 CONNECT chunked-407 trailers bypass CURLOPT_SUPPRESS_CONNECT_HEADERS and lose CURLH_CONNECT classification

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Heap-use-after-free in CURLOPT_REFERER when passed a CURLINFO_REFERER pointer

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:59am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
OpenSSL ENGINE selection omitted from mTLS connection matching

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:59am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
TLS session resumption client cert bypass with CURLOPT_SSL_CTX_FUNCTION

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Authentication Bypass by Primary Weakness
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: causalsecurity
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 7:41am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
[Atlas Browser]Bypass the full-screen notification security layer by displaying a permission dialog to open an external app

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
[Atlas Browser]Bypassing Full-Screen Notification via Right-Click Context Menu Leads to Spoofing Attacks

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Use-After-Free in BTREE Index Traversal via Stale key_version in heap_update() in MariaDB Server

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Use After Free
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: lukas_kupczyk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026, 4:05pm (UTC)
🐞 Source: HackerOne

A use-after-free vulnerability was discovered in the MEMORY (HEAP) storage engine of MariaDB Server. The vulnerability was caused by incorrect handling of the `key_changed` variable in the `heap_update()` function, which could lead to stale pointers being dereferenced during BTREE index traversal. While the vulnerability could be triggered by an authenticated user with standard database privileges, no further…

πŸ‘‰ Read full report
Encoded slash traversal in the IPFS/IPNS URL rewrite escapes the configured gateway namespace

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Handling of URL Encoding (Hex Encoding)
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 8:11pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report