🎯 New Report #2946924: Authorization Header Leak via --location-trusted in Curl
🔺Severity: High
👽 Reporter: voggerloops
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-01-18
⏰ Disclosed: 2025-07-03 06:43:09
📝 Summary: null
@hackeronereports
🔺Severity: High
👽 Reporter: voggerloops
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-01-18
⏰ Disclosed: 2025-07-03 06:43:09
📝 Summary: null
@hackeronereports
🎯 New Report #2899858: Subdomain takeover on live.firefox.com
🔺Severity: Medium
👽 Reporter: martinvw
💼 Team: Mozilla
💵 Bounty: 500
🕐 Submitted: 2024-12-14
⏰ Disclosed: 2025-07-03 08:41:17
📝 Summary: The vulnerability was a subdomain takeover on live.firefox.com. The subdomain was a CNAME to www.mozilla.org, which was hosted on Fastly, but the subdomain was not registered with Fastly, allowing the reporter to claim and take over the subdomain.
@hackeronereports
🔺Severity: Medium
👽 Reporter: martinvw
💼 Team: Mozilla
💵 Bounty: 500
🕐 Submitted: 2024-12-14
⏰ Disclosed: 2025-07-03 08:41:17
📝 Summary: The vulnerability was a subdomain takeover on live.firefox.com. The subdomain was a CNAME to www.mozilla.org, which was hosted on Fastly, but the subdomain was not registered with Fastly, allowing the reporter to claim and take over the subdomain.
@hackeronereports
🎯 New Report #2686750: MozillaVPN: Elevation of Privilege via a Logic Vulnerability
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2024-08-28
⏰ Disclosed: 2025-07-03 13:34:52
📝 Summary: The MozillaVPN vulnerability was a logic flaw that allowed an unprivileged attacker to gain root privileges on macOS during the installation process. The issue was a bypass for a previously fixed vulnerability and involved the use of symbolic links.
@hackeronereports
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2024-08-28
⏰ Disclosed: 2025-07-03 13:34:52
📝 Summary: The MozillaVPN vulnerability was a logic flaw that allowed an unprivileged attacker to gain root privileges on macOS during the installation process. The issue was a bypass for a previously fixed vulnerability and involved the use of symbolic links.
@hackeronereports
🎯 New Report #2261577: MozillaVPN: Elevation of Privilege via a Race Condition Vulnerability
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2023-11-22
⏰ Disclosed: 2025-07-03 13:22:28
📝 Summary: A race condition vulnerability was discovered in Mozilla VPN that led to local privilege escalation to root on macOS. The vulnerability existed during the installation or update process, where a local attacker could replace the VPN binary with a malicious one that would execute as root. The issue was assigned a medium severity, as it required access to the local device. The vulnerability was addressed in version 2.20 of the software.
@hackeronereports
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2023-11-22
⏰ Disclosed: 2025-07-03 13:22:28
📝 Summary: A race condition vulnerability was discovered in Mozilla VPN that led to local privilege escalation to root on macOS. The vulnerability existed during the installation or update process, where a local attacker could replace the VPN binary with a malicious one that would execute as root. The issue was assigned a medium severity, as it required access to the local device. The vulnerability was addressed in version 2.20 of the software.
@hackeronereports
🎯 New Report #3235428: CRLF injection in libcurl's SMTP client via --mail-from and --mail-rcpt allows SMTP command smuggling
🔺Severity: Medium
👽 Reporter: skrcprst
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-03
⏰ Disclosed: 2025-07-03 22:57:44
📝 Summary: null
@hackeronereports
🔺Severity: Medium
👽 Reporter: skrcprst
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-03
⏰ Disclosed: 2025-07-03 22:57:44
📝 Summary: null
@hackeronereports
🎯 New Report #2981303: TLS Cipher Misconfiguration in HTTP/3/QUIC Support
🔺Severity: null
👽 Reporter: zzq1015
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-07
⏰ Disclosed: 2025-07-06 21:05:11
📝 Summary: null
📂 Report JSON File: 2981303
@hackeronereports
🔺Severity: null
👽 Reporter: zzq1015
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-07
⏰ Disclosed: 2025-07-06 21:05:11
📝 Summary: null
📂 Report JSON File: 2981303
@hackeronereports
🎯 New Report #1813453: [MK8DX Improper ranking/replay file parsing](https://hackerone.com/reports/1813453)
🔺Severity: Critical
👽 Reporter: crazy man123
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2022-12-21
⏰ Disclosed: 2025-07-06 23:23:12
📝 Summary: The vulnerability in the Mario Kart 8 Deluxe game involved improper ranking and replay file parsing. This allowed for potential exploitation, leading to potentially unintended consequences.
📂 Report JSON File: 1813453
@hackeronereports
🔺Severity: Critical
👽 Reporter: crazy man123
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2022-12-21
⏰ Disclosed: 2025-07-06 23:23:12
📝 Summary: The vulnerability in the Mario Kart 8 Deluxe game involved improper ranking and replay file parsing. This allowed for potential exploitation, leading to potentially unintended consequences.
📂 Report JSON File: 1813453
@hackeronereports
🎯 New Report #2859735: curl --continue-at confusion
🔺Severity: Medium
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-22
⏰ Disclosed: 2025-07-07 10:18:26
📝 Summary: null
📂 Report JSON File: 2859735
@hackeronereports
🔺Severity: Medium
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-22
⏰ Disclosed: 2025-07-07 10:18:26
📝 Summary: null
📂 Report JSON File: 2859735
@hackeronereports
🎯 New Report #2853023: Information Disclosure at : https://curl.se/.mailmap
🔺Severity: High
👽 Reporter: haithamzakaria
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-20
⏰ Disclosed: 2025-07-07 10:18:15
📝 Summary: null
📂 Report JSON File: 2853023
@hackeronereports
🔺Severity: High
👽 Reporter: haithamzakaria
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-20
⏰ Disclosed: 2025-07-07 10:18:15
📝 Summary: null
📂 Report JSON File: 2853023
@hackeronereports
🎯 New Report #2841436: information disclosure
🔺Severity: None
👽 Reporter: rono 07
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-14
⏰ Disclosed: 2025-07-07 10:18:05
📝 Summary: null
📂 Report JSON File: 2841436
@hackeronereports
🔺Severity: None
👽 Reporter: rono 07
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-14
⏰ Disclosed: 2025-07-07 10:18:05
📝 Summary: null
📂 Report JSON File: 2841436
@hackeronereports
🎯 New Report #2831558: netrc crlf injection
🔺Severity: null
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-09
⏰ Disclosed: 2025-07-07 10:17:55
📝 Summary: null
📂 Report JSON File: 2831558
@hackeronereports
🔺Severity: null
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-09
⏰ Disclosed: 2025-07-07 10:17:55
📝 Summary: null
📂 Report JSON File: 2831558
@hackeronereports
🎯 New Report #2861797: curl mishandles ` ` sequences in HTTP responses leading to CRLF confusions, Headers and Cookies Injection
🔺Severity: null
👽 Reporter: mdakh404
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-23
⏰ Disclosed: 2025-07-07 10:17:41
📝 Summary: null
📂 Report JSON File: 2861797
@hackeronereports
🔺Severity: null
👽 Reporter: mdakh404
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-23
⏰ Disclosed: 2025-07-07 10:17:41
📝 Summary: null
📂 Report JSON File: 2861797
@hackeronereports
🎯 New Report #2864414: Arbitrary File Deletion Vulnerability in curl Source Code via os.unlink()
🔺Severity: High
👽 Reporter: aadityaathehacker
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
⏰ Disclosed: 2025-07-07 10:17:31
📝 Summary: null
📂 Report JSON File: 2864414
@hackeronereports
🔺Severity: High
👽 Reporter: aadityaathehacker
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
⏰ Disclosed: 2025-07-07 10:17:31
📝 Summary: null
📂 Report JSON File: 2864414
@hackeronereports
🎯 New Report #2864859: -H with space prefix leads to previous header injection when used with --proxy
🔺Severity: Medium
👽 Reporter: spongebhav
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
⏰ Disclosed: 2025-07-07 10:17:20
📝 Summary: null
📂 Report JSON File: 2864859
@hackeronereports
🔺Severity: Medium
👽 Reporter: spongebhav
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
⏰ Disclosed: 2025-07-07 10:17:20
📝 Summary: null
📂 Report JSON File: 2864859
@hackeronereports
🎯 New Report #2904921: OS Command Injection (subprocess Module Usage)
🔺Severity: Low
👽 Reporter: bulter
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-17
⏰ Disclosed: 2025-07-07 10:17:09
📝 Summary: null
📂 Report JSON File: 2904921
@hackeronereports
🔺Severity: Low
👽 Reporter: bulter
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-17
⏰ Disclosed: 2025-07-07 10:17:09
📝 Summary: null
📂 Report JSON File: 2904921
@hackeronereports
🎯 New Report #2915426: Git repository found
🔺Severity: High
👽 Reporter: tefa
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-27
⏰ Disclosed: 2025-07-07 10:16:58
📝 Summary: null
📂 Report JSON File: 2915426
@hackeronereports
🔺Severity: High
👽 Reporter: tefa
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-27
⏰ Disclosed: 2025-07-07 10:16:58
📝 Summary: null
📂 Report JSON File: 2915426
@hackeronereports
🎯 New Report #3238249: Integer Overflow Risk in HTTP/2 Proxy Window Size Calculations
🔺Severity: Medium
👽 Reporter: extramayoextracheeseextrafries
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-06
⏰ Disclosed: 2025-07-07 10:16:48
📝 Summary: null
📂 Report JSON File: 3238249
@hackeronereports
🔺Severity: Medium
👽 Reporter: extramayoextracheeseextrafries
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-06
⏰ Disclosed: 2025-07-07 10:16:48
📝 Summary: null
📂 Report JSON File: 3238249
@hackeronereports
🎯 New Report #2402842: Information disclosure identified on IBM endpoint.
🔺Severity: Medium
👽 Reporter: devire
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2024-03-05
⏰ Disclosed: 2025-07-08 14:50:58
📝 Summary: The information disclosure vulnerability identified on an IBM endpoint was reported to IBM, analyzed, and remediated.
📂 Report JSON File: 2402842
@hackeronereports
🔺Severity: Medium
👽 Reporter: devire
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2024-03-05
⏰ Disclosed: 2025-07-08 14:50:58
📝 Summary: The information disclosure vulnerability identified on an IBM endpoint was reported to IBM, analyzed, and remediated.
📂 Report JSON File: 2402842
@hackeronereports
🎯 New Report #3230359: CSRF at Network feature
🔺Severity: Medium
👽 Reporter: psfauzi
🛠 State: resolved
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-30
⏰ Disclosed: 2025-07-08 14:19:58
📝 Summary: A CSRF vulnerability was found in the network feature, where an attacker could change the Network Routing settings by sending a CSRF script to the victim.
📂 Report JSON File: 3230359
@hackeronereports
🔺Severity: Medium
👽 Reporter: psfauzi
🛠 State: resolved
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-30
⏰ Disclosed: 2025-07-08 14:19:58
📝 Summary: A CSRF vulnerability was found in the network feature, where an attacker could change the Network Routing settings by sending a CSRF script to the victim.
📂 Report JSON File: 3230359
@hackeronereports
🎯 New Report #3241304: access notes without permission
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
⏰ Disclosed: 2025-07-08 19:54:37
📝 Summary: null
📂 Report JSON File: 3241304
@hackeronereports
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
⏰ Disclosed: 2025-07-08 19:54:37
📝 Summary: null
📂 Report JSON File: 3241304
@hackeronereports
🎯 New Report #3241308: Disclosure of email addresses
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
⏰ Disclosed: 2025-07-08 19:53:51
📝 Summary: null
📂 Report JSON File: 3241308
@hackeronereports
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
⏰ Disclosed: 2025-07-08 19:53:51
📝 Summary: null
📂 Report JSON File: 3241308
@hackeronereports