Bugpoint
970 subscribers
3.94K photos
3.94K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
37: `curl_mprintf` `%F` format specifier not consumed, causing variadic argument desynchronization

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Type Confusion
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
10: CURLOPT_MAXLIFETIME_CONN bypass on active HTTP/2 connections

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Improper Certificate Validation
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
56: IBM i CL wrapper `parse_command_line()` never enters quote mode

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Command Injection - Generic
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
53: HTTP/1 CONNECT chunked-407 trailers bypass CURLOPT_SUPPRESS_CONNECT_HEADERS and lose CURLH_CONNECT classification

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:58am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Heap-use-after-free in CURLOPT_REFERER when passed a CURLINFO_REFERER pointer

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:59am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
OpenSSL ENGINE selection omitted from mTLS connection matching

πŸ”Ή Severity: Low
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 6:59am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
TLS session resumption client cert bypass with CURLOPT_SSL_CTX_FUNCTION

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Authentication Bypass by Primary Weakness
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: causalsecurity
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 7:41am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
[Atlas Browser]Bypass the full-screen notification security layer by displaying a permission dialog to open an external app

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
[Atlas Browser]Bypassing Full-Screen Notification via Right-Click Context Menu Leads to Spoofing Attacks

πŸ”Ή Severity: Low
πŸ”Ή Reported To: OpenAI
πŸ”Ή Reported By: Moch_Azril
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026
🐞 Source: Bugcrowd

πŸ‘‰ Read full report
Use-After-Free in BTREE Index Traversal via Stale key_version in heap_update() in MariaDB Server

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Use After Free
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: lukas_kupczyk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2026, 4:05pm (UTC)
🐞 Source: HackerOne

A use-after-free vulnerability was discovered in the MEMORY (HEAP) storage engine of MariaDB Server. The vulnerability was caused by incorrect handling of the `key_changed` variable in the `heap_update()` function, which could lead to stale pointers being dereferenced during BTREE index traversal. While the vulnerability could be triggered by an authenticated user with standard database privileges, no further…

πŸ‘‰ Read full report
Encoded slash traversal in the IPFS/IPNS URL rewrite escapes the configured gateway namespace

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Handling of URL Encoding (Hex Encoding)
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 14, 2026, 8:11pm (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Out-of-bounds read in curl_formadd when CURLFORM_NAMELENGTH is explicitly 0

πŸ”Ή Severity: None
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: giant_anteater
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 15, 2026, 8:20am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report
Incomplete fix for CVE-2022-23915: Mercurial argument injection in HgRepository.get_file() leads to command execution

πŸ”Ή Severity: High
πŸ”Ή Weakness: OS Command Injection
πŸ”Ή Reported To: Weblate
πŸ”Ή Reported By: mask0ff
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 15, 2026, 8:36am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in Weblate, a web-based translation tool. The vulnerability was caused by an incomplete fix for a previous issue (CVE-2022-23915). Weblate passed repository-controlled filenames to Mercurial without properly escaping them, allowing filenames beginning with "-" to be interpreted as command-line options. This could be abused by an authenticated user with project-scoped component-edit…

πŸ‘‰ Read full report
Stack Buffer Overflow via Crafted keyseg->start/ keyseg->length in .MYI File (MariaDB MyISAM)

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Classic Buffer Overflow
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: lukas_kupczyk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 15, 2026, 9:37am (UTC)
🐞 Source: HackerOne

A stack buffer overflow vulnerability was discovered in the MyISAM storage engine of MariaDB. The vulnerability was caused by lack of validation of the "keyseg->start" and "keyseg->length" fields read from the .MYI file. This allowed an attacker to write data beyond the bounds of a fixed-size stack buffer, leading to a denial of service condition when a SQL query touched the affected table's key.

πŸ‘‰ Read full report
Heap Memory Disclosure via Integer Underflow in Item_func_json_arrayagg::cut_max_length in MariaDB Server

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Buffer Over-read
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: lukas_kupczyk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 15, 2026, 9:38am (UTC)
🐞 Source: HackerOne

A vulnerability was discovered in the `JSON_ARRAYAGG` aggregate function of MariaDB Server. The vulnerability was caused by an integer underflow in the `cut_max_length` function, which could allow an authenticated user to read arbitrary heap memory from the server process. The vulnerability was introduced in commit 6c573a9146caa76807db1190e0747f5befb5b170 (2020-06-15) and affected versions of MariaDB Server prior…

πŸ‘‰ Read full report
Stack Buffer-Overflow in MariaDB Charset_collation_map_st::insert_or_replace()

πŸ”Ή Severity: No Rating
πŸ”Ή Weakness: Stack Overflow
πŸ”Ή Reported To: MariaDB
πŸ”Ή Reported By: lukas_kupczyk
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 15, 2026, 9:39am (UTC)
🐞 Source: HackerOne

A stack-based buffer overflow was discovered in the MariaDB Server's `Charset_collation_map_st::insert_or_replace()` function. The function copied user-supplied charset and collation identifiers into fixed-size stack buffers using `strmake()` with the attacker-controlled token length as the size bound instead of the destination buffer size. This could have been leveraged by an authenticated user to crash the entire…

πŸ‘‰ Read full report
libcurl LDAP LDIF: entry DN and attribute names written without RFC 2849 base64 encoding, allowing server line injection

πŸ”Ή Severity: Low
πŸ”Ή Weakness: CRLF Injection
πŸ”Ή Reported To: curl
πŸ”Ή Reported By: 1rhino2
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 15, 2026, 10:11am (UTC)
🐞 Source: HackerOne

πŸ‘‰ Read full report