Hackerone Reports
227 subscribers
744 links
Last Check 2026-09-20 23:45:01
Download Telegram
🎯 New Report #3120987: [High Arbitrary File Write via Path Traversal in cURL CLI (-o, --output) (CWE-22: Improper Limitation of a Pathname to a Restricted Directory)](https://hackerone.com/reports/3120987)
🔺Severity: High
👽 Reporter: oicus
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-01
Disclosed: 2025-06-30 18:55:10
📝 Summary: null
@hackeronereports
🎯 New Report #3118915: Potential XSS vector in curl via unsanitized URL parameter handling
🔺Severity: High
👽 Reporter: redfoxsec
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-04-30
Disclosed: 2025-06-30 18:55:00
📝 Summary: null
@hackeronereports
🎯 New Report #3045390: Double free caused by mqtt doing()
🔺Severity: None
👽 Reporter: tdp3kel9g
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-18
Disclosed: 2025-06-30 18:54:49
📝 Summary: null
@hackeronereports
🎯 New Report #3037583: Buffer Overflow in curl's Rustls Backend
🔺Severity: null
👽 Reporter: cyberguardianrd
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-14
Disclosed: 2025-06-30 18:54:26
📝 Summary: null
@hackeronereports
🎯 New Report #3230082: Stack-based Buffer Overflow in TELNET NEW ENV Option Handling
🔺Severity: High
👽 Reporter: agent 0
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-30
Disclosed: 2025-06-30 18:35:20
📝 Summary: null
@hackeronereports
🎯 New Report #3124490: Speculative Execution Side-Channel in `curl`
🔺Severity: Medium
👽 Reporter: evilginx1
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-03
Disclosed: 2025-07-01 14:09:27
📝 Summary: null
@hackeronereports
🎯 New Report #3226502: arbitrary file read via `file://` path traversal with `--path-as-is`
🔺Severity: Medium
👽 Reporter: demsese
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-06-27
Disclosed: 2025-07-01 14:08:38
📝 Summary: null
@hackeronereports
🎯 New Report #3156384: Heap buffer overflow vulnerability in conncache.c: incorrect use of pointer arrays resulting in out-of-bounds memory writes.
🔺Severity: Medium
👽 Reporter: freak coding
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-21
Disclosed: 2025-07-01 14:08:26
📝 Summary: null
@hackeronereports
🎯 New Report #3135673: curl -OJ allows creating custom .curlrc file which allows exfiltrating private data, among other things
🔺Severity: None
👽 Reporter: wolfsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-08
Disclosed: 2025-07-01 14:07:45
📝 Summary: null
@hackeronereports
🎯 New Report #3133253: curl easy header runs at O(N) or worse and can be abused to use minute(s) of CPU time
🔺Severity: null
👽 Reporter: wolfsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-07
Disclosed: 2025-07-01 14:07:31
📝 Summary: null
@hackeronereports
🎯 New Report #3231321: HTTP Proxy Bypass via `CURLOPT CUSTOMREQUEST` Verb Tunneling
🔺Severity: High
👽 Reporter: alphox
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-01
Disclosed: 2025-07-01 14:20:30
📝 Summary: null
@hackeronereports
🎯 New Report #3023139: Memory leak of ftp (with proxy reuse)
🔺Severity: None
👽 Reporter: catenacyber
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-05
Disclosed: 2025-07-01 16:25:41
📝 Summary: null
@hackeronereports
🎯 New Report #3000639: curl doesn't hide credentials in /proc/XXX/cmdline provided via CLI arguments
🔺Severity: Medium
👽 Reporter: stogusho
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-19
Disclosed: 2025-07-03 06:43:39
📝 Summary: null
@hackeronereports
🎯 New Report #2941920: Elevation of Privileges (EoP) vulnerabilities related to the some easy options on Windows
🔺Severity: High
👽 Reporter: justlikebono official
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-01-16
Disclosed: 2025-07-03 06:43:25
📝 Summary: null
@hackeronereports
🎯 New Report #2946924: Authorization Header Leak via --location-trusted in Curl
🔺Severity: High
👽 Reporter: voggerloops
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-01-18
Disclosed: 2025-07-03 06:43:09
📝 Summary: null
@hackeronereports
🎯 New Report #2899858: Subdomain takeover on live.firefox.com
🔺Severity: Medium
👽 Reporter: martinvw
💼 Team: Mozilla
💵 Bounty: 500
🕐 Submitted: 2024-12-14
Disclosed: 2025-07-03 08:41:17
📝 Summary: The vulnerability was a subdomain takeover on live.firefox.com. The subdomain was a CNAME to www.mozilla.org, which was hosted on Fastly, but the subdomain was not registered with Fastly, allowing the reporter to claim and take over the subdomain.
@hackeronereports
🎯 New Report #2686750: MozillaVPN: Elevation of Privilege via a Logic Vulnerability
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2024-08-28
Disclosed: 2025-07-03 13:34:52
📝 Summary: The MozillaVPN vulnerability was a logic flaw that allowed an unprivileged attacker to gain root privileges on macOS during the installation process. The issue was a bypass for a previously fixed vulnerability and involved the use of symbolic links.
@hackeronereports
🎯 New Report #2261577: MozillaVPN: Elevation of Privilege via a Race Condition Vulnerability
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2023-11-22
Disclosed: 2025-07-03 13:22:28
📝 Summary: A race condition vulnerability was discovered in Mozilla VPN that led to local privilege escalation to root on macOS. The vulnerability existed during the installation or update process, where a local attacker could replace the VPN binary with a malicious one that would execute as root. The issue was assigned a medium severity, as it required access to the local device. The vulnerability was addressed in version 2.20 of the software.
@hackeronereports
🎯 New Report #3235428: CRLF injection in libcurl's SMTP client via --mail-from and --mail-rcpt allows SMTP command smuggling
🔺Severity: Medium
👽 Reporter: skrcprst
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-03
Disclosed: 2025-07-03 22:57:44
📝 Summary: null
@hackeronereports
🎯 New Report #2981303: TLS Cipher Misconfiguration in HTTP/3/QUIC Support
🔺Severity: null
👽 Reporter: zzq1015
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-07
Disclosed: 2025-07-06 21:05:11
📝 Summary: null
📂 Report JSON File: 2981303
@hackeronereports
🎯 New Report #1813453: [MK8DX Improper ranking/replay file parsing](https://hackerone.com/reports/1813453)
🔺Severity: Critical
👽 Reporter: crazy man123
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2022-12-21
Disclosed: 2025-07-06 23:23:12
📝 Summary: The vulnerability in the Mario Kart 8 Deluxe game involved improper ranking and replay file parsing. This allowed for potential exploitation, leading to potentially unintended consequences.
📂 Report JSON File: 1813453
@hackeronereports