Hackerone Reports
227 subscribers
744 links
Last Check 2026-09-20 23:45:01
Download Telegram
🎯 New Report #3089595: Memory leak from doh write cb
🔺Severity: None
👽 Reporter: catenacyber
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-11
Disclosed: 2025-06-29 19:12:35
📝 Summary: null
@hackeronereports
🎯 New Report #3229490: Heap Buffer Overflow in libcurl curl slist append via Unterminated String
🔺Severity: High
👽 Reporter: geeknik
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-29
Disclosed: 2025-06-30 07:23:15
📝 Summary: null
@hackeronereports
🎯 New Report #2914705: Making transfer v2 channel unupgradable through the forwarding
🔺Severity: Low
👽 Reporter: unknown feature
💼 Team: Cosmos
💵 Bounty: null
🕐 Submitted: 2024-12-26
Disclosed: 2025-06-30 12:46:29
📝 Summary: The transfer v2 channel can become unupgradable through the forwarding functionality. The forwarding process can create packet commitments on a legitimate channel, which cannot be deleted due to the lack of acknowledgments from a malicious channel. This results in the legitimate channel being unable to transition to the "FLUSHCOMPLETE" state, preventing the channel upgrade from being completed.
@hackeronereports
🤩1
🎯 New Report #2917368: Replacing ICA active channel during the upgrade and a bit more
🔺Severity: Low
👽 Reporter: unknown feature
💼 Team: Cosmos
💵 Bounty: null
🕐 Submitted: 2024-12-30
Disclosed: 2025-06-30 12:46:22
📝 Summary: The active channel on the ICA controller was set during the channel acknowledgement, which was a check-then-act operation that was not atomic. The active channel on the ICA host was set during the channel open confirmation, but the check for the channel existence was not atomic. This allowed an attacker to create a malicious channel and set it as the active channel during an upgrade, preventing the host chain from deserializing ICA transactions until another upgrade was performed.
@hackeronereports
🎯 New Report #3136790: Unlock underage blocked app without support interaction using airplane mode
🔺Severity: Low
👽 Reporter: polem4rch
💼 Team: Tools for Humanity
💵 Bounty: 300
🕐 Submitted: 2025-05-09
Disclosed: 2025-06-30 11:20:50
📝 Summary: null
@hackeronereports
😁1
🎯 New Report #2947762: RXSS AT https://proze.yelp.com/tmsubscribe.net/vidsn.aspx
🔺Severity: Medium
👽 Reporter: 0xold
💼 Team: Yelp
💵 Bounty: null
🕐 Submitted: 2025-01-19
Disclosed: 2025-06-30 15:06:44
📝 Summary: The proze.yelp.com domain was vulnerable to Cross-Site Scripting (XSS) attacks, which allowed the injection of malicious scripts that could affect the security of users of the domain.
@hackeronereports
🎯 New Report #3120969: [High MITM via Insecure CA Path Handling in cURL (--capath, CURLOPT CAPATH) (CWE-494: Download of Code Without Integrity Check)](https://hackerone.com/reports/3120969)
🔺Severity: High
👽 Reporter: oicus
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-01
Disclosed: 2025-06-30 18:55:20
📝 Summary: null
@hackeronereports
🎯 New Report #3120987: [High Arbitrary File Write via Path Traversal in cURL CLI (-o, --output) (CWE-22: Improper Limitation of a Pathname to a Restricted Directory)](https://hackerone.com/reports/3120987)
🔺Severity: High
👽 Reporter: oicus
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-01
Disclosed: 2025-06-30 18:55:10
📝 Summary: null
@hackeronereports
🎯 New Report #3118915: Potential XSS vector in curl via unsanitized URL parameter handling
🔺Severity: High
👽 Reporter: redfoxsec
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-30
Disclosed: 2025-06-30 18:55:00
📝 Summary: null
@hackeronereports
🎯 New Report #3045390: Double free caused by mqtt doing()
🔺Severity: None
👽 Reporter: tdp3kel9g
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-18
Disclosed: 2025-06-30 18:54:49
📝 Summary: null
@hackeronereports
🎯 New Report #3037583: Buffer Overflow in curl's Rustls Backend
🔺Severity: null
👽 Reporter: cyberguardianrd
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-14
Disclosed: 2025-06-30 18:54:26
📝 Summary: null
@hackeronereports
🎯 New Report #3230082: Stack-based Buffer Overflow in TELNET NEW ENV Option Handling
🔺Severity: High
👽 Reporter: agent 0
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-30
Disclosed: 2025-06-30 18:35:20
📝 Summary: null
@hackeronereports
🎯 New Report #3124490: Speculative Execution Side-Channel in `curl`
🔺Severity: Medium
👽 Reporter: evilginx1
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-03
Disclosed: 2025-07-01 14:09:27
📝 Summary: null
@hackeronereports
🎯 New Report #3226502: arbitrary file read via `file://` path traversal with `--path-as-is`
🔺Severity: Medium
👽 Reporter: demsese
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-27
Disclosed: 2025-07-01 14:08:38
📝 Summary: null
@hackeronereports
🎯 New Report #3156384: Heap buffer overflow vulnerability in conncache.c: incorrect use of pointer arrays resulting in out-of-bounds memory writes.
🔺Severity: Medium
👽 Reporter: freak coding
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-21
Disclosed: 2025-07-01 14:08:26
📝 Summary: null
@hackeronereports
🎯 New Report #3135673: curl -OJ allows creating custom .curlrc file which allows exfiltrating private data, among other things
🔺Severity: None
👽 Reporter: wolfsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-08
Disclosed: 2025-07-01 14:07:45
📝 Summary: null
@hackeronereports
🎯 New Report #3133253: curl easy header runs at O(N) or worse and can be abused to use minute(s) of CPU time
🔺Severity: null
👽 Reporter: wolfsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-07
Disclosed: 2025-07-01 14:07:31
📝 Summary: null
@hackeronereports
🎯 New Report #3231321: HTTP Proxy Bypass via `CURLOPT CUSTOMREQUEST` Verb Tunneling
🔺Severity: High
👽 Reporter: alphox
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-01
Disclosed: 2025-07-01 14:20:30
📝 Summary: null
@hackeronereports
🎯 New Report #3023139: Memory leak of ftp (with proxy reuse)
🔺Severity: None
👽 Reporter: catenacyber
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-05
Disclosed: 2025-07-01 16:25:41
📝 Summary: null
@hackeronereports
🎯 New Report #3000639: curl doesn't hide credentials in /proc/XXX/cmdline provided via CLI arguments
🔺Severity: Medium
👽 Reporter: stogusho
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-19
Disclosed: 2025-07-03 06:43:39
📝 Summary: null
@hackeronereports
🎯 New Report #2941920: Elevation of Privileges (EoP) vulnerabilities related to the some easy options on Windows
🔺Severity: High
👽 Reporter: justlikebono official
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-01-16
Disclosed: 2025-07-03 06:43:25
📝 Summary: null
@hackeronereports