Hackerone Reports
222 subscribers
722 links
Last Check 2026-09-15 03:45:01
Download Telegram
🎯 New Report #2817648: Improper error handling in async cryptographic operations crashes process
🔺Severity: High
👽 Reporter: tniessen
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2024-11-02
Disclosed: 2025-05-14 22:30:56
📝 Summary: The C method SignTraits::DeriveBits() incorrectly called ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process.
@hackeronereports
🎯 New Report #3062122: [Xenoblade Chronicles X: Definitive Edition Unrestricted RPCs allow DoS and writing arbitrary flags remotely](https://hackerone.com/reports/3062122)
🔺Severity: Critical
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-31
Disclosed: 2025-05-15 00:11:16
📝 Summary: The Xenoblade Chronicles X: Definitive Edition vulnerability allowed attackers to perform Denial-of-Service (DoS) attacks and write arbitrary flags remotely due to unrestricted Remote Procedure Calls (RPCs).
@hackeronereports
🎯 New Report #3052880: [Xenoblade Chronicles X: Definitive Edition Improper validation of names allows injecting formatting tags and bypassing profanity filter](https://hackerone.com/reports/3052880)
🔺Severity: Medium
👽 Reporter: roccodev
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2025-03-23
Disclosed: 2025-05-15 00:11:06
📝 Summary: The vulnerability in Xenoblade Chronicles X: Definitive Edition allowed improper validation of names, enabling the injection of formatting tags and bypassing the profanity filter.
@hackeronereports
🎯 New Report #3085889: Weak Rate Limiting Controls in the (LOGIN) page Expose System to Brute Force and DoS Attacks
🔺Severity: Critical
👽 Reporter: hajjaj-
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-09
Disclosed: 2025-05-15 11:11:04
📝 Summary: null
@hackeronereports
🎯 New Report #3099816: Open Redirect Vulnerability in OAuth Flow Leading to Potential Phishing Attack
🔺Severity: Low
👽 Reporter: delsec
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-04-18
Disclosed: 2025-05-15 11:10:40
📝 Summary: null
@hackeronereports
🎯 New Report #3056937: Bedrock Guardrails Evasion with Prompt Formatting
🔺Severity: None
👽 Reporter: nkirk-nrlabs
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-25
Disclosed: 2025-05-15 16:12:27
📝 Summary: null
@hackeronereports
🎯 New Report #2885269: Shopify Partners Invitation Process Allows Privilege Escalation Without Email Verification
🔺Severity: Medium
👽 Reporter: mr asg
💼 Team: Shopify
💵 Bounty: 3500
🕐 Submitted: 2024-12-06
Disclosed: 2025-05-15 18:25:56
📝 Summary: The Shopify Partners invitation process allowed privilege escalation without email verification. The vulnerability permitted unauthorized users to gain access to Shopify Partners accounts and escalate their privileges by creating accounts using the email addresses of invited owners and accepting the invitations.
@hackeronereports
🎯 New Report #2802817: Any WARP User Can Access Organization-Specific Application
🔺Severity: None
👽 Reporter: jai-kandepu
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: null
🕐 Submitted: 2024-10-25
Disclosed: 2025-05-19 21:58:31
📝 Summary: null
@hackeronereports
🎯 New Report #3148937: `Curl socketpair()` fallback vulnerable to man-in-the-middle attack
🔺Severity: null
👽 Reporter: jmanojlovich
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-15
Disclosed: 2025-05-20 06:51:27
📝 Summary: null
@hackeronereports
🎯 New Report #3158093: Memory Leak in libcurl via Location Header Handling (CWE-770)
🔺Severity: High
👽 Reporter: darkroomdragon
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-22
Disclosed: 2025-05-22 07:19:09
📝 Summary: null
@hackeronereports
🎯 New Report #1981441: Dynamic fee algorithm doesn't check for zero fee
🔺Severity: Low
👽 Reporter: sech1
💼 Team: Monero
💵 Bounty: null
🕐 Submitted: 2023-05-10
Disclosed: 2025-05-23 14:25:46
📝 Summary: The dynamic fee algorithm in the Monero blockchain did not properly check for a zero fee, which could have allowed an attacker to flood the network with transactions at no cost, potentially leading to unlimited blockchain growth.
@hackeronereports
🎯 New Report #2338094: RPC service DOS
🔺Severity: Medium
👽 Reporter: ptrstr
💼 Team: Monero
💵 Bounty: null
🕐 Submitted: 2024-01-28
Disclosed: 2025-05-23 14:25:17
📝 Summary: The RPC service running on port 18081 (or 28081, 38081) was vulnerable to a denial-of-service attack due to a loop iterating until the maximum range of a 64-bit unsigned integer. The vulnerability was present in all versions after the commit b030f207517f59a5122409398549a02ac23829ae, up to and including version 0.18.3.1.
@hackeronereports
🎯 New Report #2084280: WASI sandbox escape via symlink
🔺Severity: Medium
👽 Reporter: jessewilson
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2023-07-25
Disclosed: 2025-05-24 10:33:57
📝 Summary: A WASI WASM program was discovered to be able to use path symlink to read arbitrary files on the host machine by creating a symlink in a preopen to a different location on the local file system, thereby escaping the WASI sandbox.
@hackeronereports
🎯 New Report #2939104: CVE-2024-56374: Denial-of-service vulnerability in IPv6 validation
🔺Severity: Medium
👽 Reporter: sav
💼 Team: Internet Bug Bounty
💵 Bounty: 2162
🕐 Submitted: 2025-01-15
Disclosed: 2025-05-27 12:26:37
📝 Summary: A denial-of-service vulnerability was discovered in Django's IPv6 validation. The lack of an upper bound limit enforcement in strings passed during IPv6 validation could lead to a potential denial-of-service attack. The vulnerable functions, clean ipv6 address and is valid ipv6 address, as well as the django.forms.GenericIPAddressField form field, have been updated to address this issue.
@hackeronereports
🎯 New Report #2978267: TLS client authentication can be bypassed due to ticket resumption
🔺Severity: Medium
👽 Reporter: snhebrok
💼 Team: Internet Bug Bounty
💵 Bounty: 2162
🕐 Submitted: 2025-02-06
Disclosed: 2025-05-27 13:18:05
📝 Summary: The TLS client authentication can be bypassed due to ticket resumption. The issue was that TLS session tickets were not properly isolated for multiple virtual hosts in one server. This allowed a ticket issued for one virtual host to be resumed at a different virtual host, circumventing client authentication. The vulnerability affected both the NGINX http and NGINX stream modules.
@hackeronereports
🎯 New Report #2905013: [SECURITY CVE-2024-50379 Apache Tomcat - RCE via write-enabled default servlet](https://hackerone.com/reports/2905013)
🔺Severity: High
👽 Reporter: nacl 123
💼 Team: Internet Bug Bounty
💵 Bounty: null
🕐 Submitted: 2024-12-17
Disclosed: 2025-05-27 15:31:48
📝 Summary: A vulnerability was discovered in Apache Tomcat where a race condition could be triggered on a Windows machine with a write-enabled default servlet, leading to remote code execution. The issue was caused by the case-insensitive nature of the file system, which allowed an uploaded file to be treated as a JSP script.
@hackeronereports
🎯 New Report #3078856: Apache Airflow Sql injection by authenticated user
🔺Severity: Low
👽 Reporter: nxczje
💼 Team: Internet Bug Bounty
💵 Bounty: 505
🕐 Submitted: 2025-04-05
Disclosed: 2025-05-27 17:55:18
📝 Summary: Apache Airflow versions 2.10.5 were affected by a vulnerability that allowed an attacker to manipulate query construction, leading to an SQL Injection vulnerability. The vulnerability was present in the SQLColumnCheckOperator, which could result in remote code execution.
@hackeronereports
🎯 New Report #2828641: unauthorized access and add user and change personal information all users
🔺Severity: Critical
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-07
Disclosed: 2025-05-27 20:53:18
📝 Summary: The report describes a vulnerability in the ██████████ website, where unauthorized access to an API endpoint allowed attackers to add new users and modify personal information of existing users. The vulnerability was classified as Improper Access Control. The issue stemmed from the absence of proper authentication and authorization mechanisms on the ██████████ endpoint, which handled user registration and profile updates. This vulnerability allowed anyone to create new user accounts or modify existing user information without requiring any authentication. Additionally, the vulnerability was compounded by a predictable user identifier system (4-digit codes) that could be easily enumerated through brute force methods to identify valid user profiles through the ██████████ endpoint.
@hackeronereports
🎯 New Report #2828720: Customer Data Exposure via Insecure Endpoint of coupon
🔺Severity: Medium
👽 Reporter: bughunter0x7
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2024-11-08
Disclosed: 2025-05-27 20:33:00
📝 Summary: A security vulnerability was identified in the Royal Canin Greece website. An insecure API endpoint was exposed that allowed unauthorized access to customer information without requiring authentication. The endpoint related to coupon functionality and revealed sensitive customer data, including company names, phone numbers, email addresses, tokens, and coupon details. The vulnerability was classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) with a medium severity rating (CVSS score 5.7). Customer information could be accessed by modifying a parameter in the request.
@hackeronereports
🎯 New Report #3068422: Non-Production API Endpoints for the Neptune Graph Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-31
Disclosed: 2025-05-27 22:39:02
📝 Summary: The Neptune Graph service has 7 non-production API endpoints that can be accessed with standard IAM credentials without logging to CloudTrail. This allows for silent permission enumeration, where an adversary can determine the permissions of compromised credentials without generating any CloudTrail logs.
@hackeronereports
🎯 New Report #3092085: Non-Production API Endpoints for the Route 53 Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-04-14
Disclosed: 2025-05-27 22:15:31
📝 Summary: The non-production API endpoints for the Route 53 service failed to log to CloudTrail, resulting in silent permission enumeration. Two non-production endpoints were found that could be used with standard IAM credentials without logging to CloudTrail. This allowed an adversary to perform permission enumeration activities without generating any logs.
@hackeronereports