Hackerone Reports
227 subscribers
744 links
Last Check 2026-09-20 18:45:01
Download Telegram
🎯 New Report #3135673: curl -OJ allows creating custom .curlrc file which allows exfiltrating private data, among other things
🔺Severity: None
👽 Reporter: wolfsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-08
Disclosed: 2025-07-01 14:07:45
📝 Summary: null
@hackeronereports
🎯 New Report #3133253: curl easy header runs at O(N) or worse and can be abused to use minute(s) of CPU time
🔺Severity: null
👽 Reporter: wolfsage
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-07
Disclosed: 2025-07-01 14:07:31
📝 Summary: null
@hackeronereports
🎯 New Report #3231321: HTTP Proxy Bypass via `CURLOPT CUSTOMREQUEST` Verb Tunneling
🔺Severity: High
👽 Reporter: alphox
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-01
Disclosed: 2025-07-01 14:20:30
📝 Summary: null
@hackeronereports
🎯 New Report #3023139: Memory leak of ftp (with proxy reuse)
🔺Severity: None
👽 Reporter: catenacyber
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-03-05
Disclosed: 2025-07-01 16:25:41
📝 Summary: null
@hackeronereports
🎯 New Report #3000639: curl doesn't hide credentials in /proc/XXX/cmdline provided via CLI arguments
🔺Severity: Medium
👽 Reporter: stogusho
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-19
Disclosed: 2025-07-03 06:43:39
📝 Summary: null
@hackeronereports
🎯 New Report #2941920: Elevation of Privileges (EoP) vulnerabilities related to the some easy options on Windows
🔺Severity: High
👽 Reporter: justlikebono official
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-01-16
Disclosed: 2025-07-03 06:43:25
📝 Summary: null
@hackeronereports
🎯 New Report #2946924: Authorization Header Leak via --location-trusted in Curl
🔺Severity: High
👽 Reporter: voggerloops
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-01-18
Disclosed: 2025-07-03 06:43:09
📝 Summary: null
@hackeronereports
🎯 New Report #2899858: Subdomain takeover on live.firefox.com
🔺Severity: Medium
👽 Reporter: martinvw
💼 Team: Mozilla
💵 Bounty: 500
🕐 Submitted: 2024-12-14
Disclosed: 2025-07-03 08:41:17
📝 Summary: The vulnerability was a subdomain takeover on live.firefox.com. The subdomain was a CNAME to www.mozilla.org, which was hosted on Fastly, but the subdomain was not registered with Fastly, allowing the reporter to claim and take over the subdomain.
@hackeronereports
🎯 New Report #2686750: MozillaVPN: Elevation of Privilege via a Logic Vulnerability
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2024-08-28
Disclosed: 2025-07-03 13:34:52
📝 Summary: The MozillaVPN vulnerability was a logic flaw that allowed an unprivileged attacker to gain root privileges on macOS during the installation process. The issue was a bypass for a previously fixed vulnerability and involved the use of symbolic links.
@hackeronereports
🎯 New Report #2261577: MozillaVPN: Elevation of Privilege via a Race Condition Vulnerability
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2023-11-22
Disclosed: 2025-07-03 13:22:28
📝 Summary: A race condition vulnerability was discovered in Mozilla VPN that led to local privilege escalation to root on macOS. The vulnerability existed during the installation or update process, where a local attacker could replace the VPN binary with a malicious one that would execute as root. The issue was assigned a medium severity, as it required access to the local device. The vulnerability was addressed in version 2.20 of the software.
@hackeronereports
🎯 New Report #3235428: CRLF injection in libcurl's SMTP client via --mail-from and --mail-rcpt allows SMTP command smuggling
🔺Severity: Medium
👽 Reporter: skrcprst
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-03
Disclosed: 2025-07-03 22:57:44
📝 Summary: null
@hackeronereports
🎯 New Report #2981303: TLS Cipher Misconfiguration in HTTP/3/QUIC Support
🔺Severity: null
👽 Reporter: zzq1015
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-07
Disclosed: 2025-07-06 21:05:11
📝 Summary: null
📂 Report JSON File: 2981303
@hackeronereports
🎯 New Report #1813453: [MK8DX Improper ranking/replay file parsing](https://hackerone.com/reports/1813453)
🔺Severity: Critical
👽 Reporter: crazy man123
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2022-12-21
Disclosed: 2025-07-06 23:23:12
📝 Summary: The vulnerability in the Mario Kart 8 Deluxe game involved improper ranking and replay file parsing. This allowed for potential exploitation, leading to potentially unintended consequences.
📂 Report JSON File: 1813453
@hackeronereports
🎯 New Report #2859735: curl --continue-at confusion
🔺Severity: Medium
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-22
Disclosed: 2025-07-07 10:18:26
📝 Summary: null
📂 Report JSON File: 2859735
@hackeronereports
🎯 New Report #2853023: Information Disclosure at : https://curl.se/.mailmap
🔺Severity: High
👽 Reporter: haithamzakaria
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-20
Disclosed: 2025-07-07 10:18:15
📝 Summary: null
📂 Report JSON File: 2853023
@hackeronereports
🎯 New Report #2841436: information disclosure
🔺Severity: None
👽 Reporter: rono 07
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-14
Disclosed: 2025-07-07 10:18:05
📝 Summary: null
📂 Report JSON File: 2841436
@hackeronereports
🎯 New Report #2831558: netrc crlf injection
🔺Severity: null
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-09
Disclosed: 2025-07-07 10:17:55
📝 Summary: null
📂 Report JSON File: 2831558
@hackeronereports
🎯 New Report #2861797: curl mishandles ` ` sequences in HTTP responses leading to CRLF confusions, Headers and Cookies Injection
🔺Severity: null
👽 Reporter: mdakh404
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-23
Disclosed: 2025-07-07 10:17:41
📝 Summary: null
📂 Report JSON File: 2861797
@hackeronereports
🎯 New Report #2864414: Arbitrary File Deletion Vulnerability in curl Source Code via os.unlink()
🔺Severity: High
👽 Reporter: aadityaathehacker
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
Disclosed: 2025-07-07 10:17:31
📝 Summary: null
📂 Report JSON File: 2864414
@hackeronereports
🎯 New Report #2864859: -H with space prefix leads to previous header injection when used with --proxy
🔺Severity: Medium
👽 Reporter: spongebhav
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
Disclosed: 2025-07-07 10:17:20
📝 Summary: null
📂 Report JSON File: 2864859
@hackeronereports
🎯 New Report #2904921: OS Command Injection (subprocess Module Usage)
🔺Severity: Low
👽 Reporter: bulter
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-17
Disclosed: 2025-07-07 10:17:09
📝 Summary: null
📂 Report JSON File: 2904921
@hackeronereports