OpenSSL ENGINE selection omitted from mTLS connection matching
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:59am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 6:59am (UTC)
π Source: HackerOne
π Read full report
TLS session resumption client cert bypass with CURLOPT_SSL_CTX_FUNCTION
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: causalsecurity
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 7:41am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Authentication Bypass by Primary Weakness
πΉ Reported To: curl
πΉ Reported By: causalsecurity
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 7:41am (UTC)
π Source: HackerOne
π Read full report
[Atlas Browser]Bypass the full-screen notification security layer by displaying a permission dialog to open an external app
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
[Atlas Browser]Bypassing Full-Screen Notification via Right-Click Context Menu Leads to Spoofing Attacks
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
πΉ Severity: Low
πΉ Reported To: OpenAI
πΉ Reported By: Moch_Azril
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026
π Source: Bugcrowd
π Read full report
Use-After-Free in BTREE Index Traversal via Stale key_version in heap_update() in MariaDB Server
πΉ Severity: No Rating
πΉ Weakness: Use After Free
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026, 4:05pm (UTC)
π Source: HackerOne
A use-after-free vulnerability was discovered in the MEMORY (HEAP) storage engine of MariaDB Server. The vulnerability was caused by incorrect handling of the `key_changed` variable in the `heap_update()` function, which could lead to stale pointers being dereferenced during BTREE index traversal. While the vulnerability could be triggered by an authenticated user with standard database privileges, no furtherβ¦
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Use After Free
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2026, 4:05pm (UTC)
π Source: HackerOne
A use-after-free vulnerability was discovered in the MEMORY (HEAP) storage engine of MariaDB Server. The vulnerability was caused by incorrect handling of the `key_changed` variable in the `heap_update()` function, which could lead to stale pointers being dereferenced during BTREE index traversal. While the vulnerability could be triggered by an authenticated user with standard database privileges, no furtherβ¦
π Read full report
Encoded slash traversal in the IPFS/IPNS URL rewrite escapes the configured gateway namespace
πΉ Severity: Medium
πΉ Weakness: Improper Handling of URL Encoding (Hex Encoding)
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 8:11pm (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Medium
πΉ Weakness: Improper Handling of URL Encoding (Hex Encoding)
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 14, 2026, 8:11pm (UTC)
π Source: HackerOne
π Read full report
Out-of-bounds read in curl_formadd when CURLFORM_NAMELENGTH is explicitly 0
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 15, 2026, 8:20am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: None
πΉ Reported To: curl
πΉ Reported By: giant_anteater
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 15, 2026, 8:20am (UTC)
π Source: HackerOne
π Read full report
Incomplete fix for CVE-2022-23915: Mercurial argument injection in HgRepository.get_file() leads to command execution
πΉ Severity: High
πΉ Weakness: OS Command Injection
πΉ Reported To: Weblate
πΉ Reported By: mask0ff
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2026, 8:36am (UTC)
π Source: HackerOne
A vulnerability was discovered in Weblate, a web-based translation tool. The vulnerability was caused by an incomplete fix for a previous issue (CVE-2022-23915). Weblate passed repository-controlled filenames to Mercurial without properly escaping them, allowing filenames beginning with "-" to be interpreted as command-line options. This could be abused by an authenticated user with project-scoped component-editβ¦
π Read full report
πΉ Severity: High
πΉ Weakness: OS Command Injection
πΉ Reported To: Weblate
πΉ Reported By: mask0ff
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2026, 8:36am (UTC)
π Source: HackerOne
A vulnerability was discovered in Weblate, a web-based translation tool. The vulnerability was caused by an incomplete fix for a previous issue (CVE-2022-23915). Weblate passed repository-controlled filenames to Mercurial without properly escaping them, allowing filenames beginning with "-" to be interpreted as command-line options. This could be abused by an authenticated user with project-scoped component-editβ¦
π Read full report
Stack Buffer Overflow via Crafted keyseg->start/ keyseg->length in .MYI File (MariaDB MyISAM)
πΉ Severity: No Rating
πΉ Weakness: Classic Buffer Overflow
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2026, 9:37am (UTC)
π Source: HackerOne
A stack buffer overflow vulnerability was discovered in the MyISAM storage engine of MariaDB. The vulnerability was caused by lack of validation of the "keyseg->start" and "keyseg->length" fields read from the .MYI file. This allowed an attacker to write data beyond the bounds of a fixed-size stack buffer, leading to a denial of service condition when a SQL query touched the affected table's key.
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Classic Buffer Overflow
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2026, 9:37am (UTC)
π Source: HackerOne
A stack buffer overflow vulnerability was discovered in the MyISAM storage engine of MariaDB. The vulnerability was caused by lack of validation of the "keyseg->start" and "keyseg->length" fields read from the .MYI file. This allowed an attacker to write data beyond the bounds of a fixed-size stack buffer, leading to a denial of service condition when a SQL query touched the affected table's key.
π Read full report
Heap Memory Disclosure via Integer Underflow in Item_func_json_arrayagg::cut_max_length in MariaDB Server
πΉ Severity: No Rating
πΉ Weakness: Buffer Over-read
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2026, 9:38am (UTC)
π Source: HackerOne
A vulnerability was discovered in the `JSON_ARRAYAGG` aggregate function of MariaDB Server. The vulnerability was caused by an integer underflow in the `cut_max_length` function, which could allow an authenticated user to read arbitrary heap memory from the server process. The vulnerability was introduced in commit 6c573a9146caa76807db1190e0747f5befb5b170 (2020-06-15) and affected versions of MariaDB Server priorβ¦
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Buffer Over-read
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2026, 9:38am (UTC)
π Source: HackerOne
A vulnerability was discovered in the `JSON_ARRAYAGG` aggregate function of MariaDB Server. The vulnerability was caused by an integer underflow in the `cut_max_length` function, which could allow an authenticated user to read arbitrary heap memory from the server process. The vulnerability was introduced in commit 6c573a9146caa76807db1190e0747f5befb5b170 (2020-06-15) and affected versions of MariaDB Server priorβ¦
π Read full report
Stack Buffer-Overflow in MariaDB Charset_collation_map_st::insert_or_replace()
πΉ Severity: No Rating
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2026, 9:39am (UTC)
π Source: HackerOne
A stack-based buffer overflow was discovered in the MariaDB Server's `Charset_collation_map_st::insert_or_replace()` function. The function copied user-supplied charset and collation identifiers into fixed-size stack buffers using `strmake()` with the attacker-controlled token length as the size bound instead of the destination buffer size. This could have been leveraged by an authenticated user to crash the entireβ¦
π Read full report
πΉ Severity: No Rating
πΉ Weakness: Stack Overflow
πΉ Reported To: MariaDB
πΉ Reported By: lukas_kupczyk
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2026, 9:39am (UTC)
π Source: HackerOne
A stack-based buffer overflow was discovered in the MariaDB Server's `Charset_collation_map_st::insert_or_replace()` function. The function copied user-supplied charset and collation identifiers into fixed-size stack buffers using `strmake()` with the attacker-controlled token length as the size bound instead of the destination buffer size. This could have been leveraged by an authenticated user to crash the entireβ¦
π Read full report
libcurl LDAP LDIF: entry DN and attribute names written without RFC 2849 base64 encoding, allowing server line injection
πΉ Severity: Low
πΉ Weakness: CRLF Injection
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 15, 2026, 10:11am (UTC)
π Source: HackerOne
π Read full report
πΉ Severity: Low
πΉ Weakness: CRLF Injection
πΉ Reported To: curl
πΉ Reported By: 1rhino2
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 15, 2026, 10:11am (UTC)
π Source: HackerOne
π Read full report