Hackerone Reports
227 subscribers
743 links
Last Check 2026-09-20 10:45:01
Download Telegram
🎯 New Report #3235428: CRLF injection in libcurl's SMTP client via --mail-from and --mail-rcpt allows SMTP command smuggling
🔺Severity: Medium
👽 Reporter: skrcprst
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-03
Disclosed: 2025-07-03 22:57:44
📝 Summary: null
@hackeronereports
🎯 New Report #2981303: TLS Cipher Misconfiguration in HTTP/3/QUIC Support
🔺Severity: null
👽 Reporter: zzq1015
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-07
Disclosed: 2025-07-06 21:05:11
📝 Summary: null
📂 Report JSON File: 2981303
@hackeronereports
🎯 New Report #1813453: [MK8DX Improper ranking/replay file parsing](https://hackerone.com/reports/1813453)
🔺Severity: Critical
👽 Reporter: crazy man123
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2022-12-21
Disclosed: 2025-07-06 23:23:12
📝 Summary: The vulnerability in the Mario Kart 8 Deluxe game involved improper ranking and replay file parsing. This allowed for potential exploitation, leading to potentially unintended consequences.
📂 Report JSON File: 1813453
@hackeronereports
🎯 New Report #2859735: curl --continue-at confusion
🔺Severity: Medium
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-22
Disclosed: 2025-07-07 10:18:26
📝 Summary: null
📂 Report JSON File: 2859735
@hackeronereports
🎯 New Report #2853023: Information Disclosure at : https://curl.se/.mailmap
🔺Severity: High
👽 Reporter: haithamzakaria
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-20
Disclosed: 2025-07-07 10:18:15
📝 Summary: null
📂 Report JSON File: 2853023
@hackeronereports
🎯 New Report #2841436: information disclosure
🔺Severity: None
👽 Reporter: rono 07
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-14
Disclosed: 2025-07-07 10:18:05
📝 Summary: null
📂 Report JSON File: 2841436
@hackeronereports
🎯 New Report #2831558: netrc crlf injection
🔺Severity: null
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-09
Disclosed: 2025-07-07 10:17:55
📝 Summary: null
📂 Report JSON File: 2831558
@hackeronereports
🎯 New Report #2861797: curl mishandles ` ` sequences in HTTP responses leading to CRLF confusions, Headers and Cookies Injection
🔺Severity: null
👽 Reporter: mdakh404
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-23
Disclosed: 2025-07-07 10:17:41
📝 Summary: null
📂 Report JSON File: 2861797
@hackeronereports
🎯 New Report #2864414: Arbitrary File Deletion Vulnerability in curl Source Code via os.unlink()
🔺Severity: High
👽 Reporter: aadityaathehacker
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
Disclosed: 2025-07-07 10:17:31
📝 Summary: null
📂 Report JSON File: 2864414
@hackeronereports
🎯 New Report #2864859: -H with space prefix leads to previous header injection when used with --proxy
🔺Severity: Medium
👽 Reporter: spongebhav
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
Disclosed: 2025-07-07 10:17:20
📝 Summary: null
📂 Report JSON File: 2864859
@hackeronereports
🎯 New Report #2904921: OS Command Injection (subprocess Module Usage)
🔺Severity: Low
👽 Reporter: bulter
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-17
Disclosed: 2025-07-07 10:17:09
📝 Summary: null
📂 Report JSON File: 2904921
@hackeronereports
🎯 New Report #2915426: Git repository found
🔺Severity: High
👽 Reporter: tefa
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-27
Disclosed: 2025-07-07 10:16:58
📝 Summary: null
📂 Report JSON File: 2915426
@hackeronereports
🎯 New Report #3238249: Integer Overflow Risk in HTTP/2 Proxy Window Size Calculations
🔺Severity: Medium
👽 Reporter: extramayoextracheeseextrafries
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-06
Disclosed: 2025-07-07 10:16:48
📝 Summary: null
📂 Report JSON File: 3238249
@hackeronereports
🎯 New Report #2402842: Information disclosure identified on IBM endpoint.
🔺Severity: Medium
👽 Reporter: devire
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2024-03-05
Disclosed: 2025-07-08 14:50:58
📝 Summary: The information disclosure vulnerability identified on an IBM endpoint was reported to IBM, analyzed, and remediated.
📂 Report JSON File: 2402842
@hackeronereports
🎯 New Report #3230359: CSRF at Network feature
🔺Severity: Medium
👽 Reporter: psfauzi
🛠 State: resolved
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-30
Disclosed: 2025-07-08 14:19:58
📝 Summary: A CSRF vulnerability was found in the network feature, where an attacker could change the Network Routing settings by sending a CSRF script to the victim.
📂 Report JSON File: 3230359
@hackeronereports
🎯 New Report #3241304: access notes without permission
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
Disclosed: 2025-07-08 19:54:37
📝 Summary: null
📂 Report JSON File: 3241304
@hackeronereports
🎯 New Report #3241308: Disclosure of email addresses
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
Disclosed: 2025-07-08 19:53:51
📝 Summary: null
📂 Report JSON File: 3241308
@hackeronereports
🎯 New Report #1485717: ReDoS in IPAddr
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-19
Disclosed: 2025-07-08 22:57:09
📝 Summary: The Ruby IPAddr library was found to be vulnerable to a ReDoS (Regular Expression Denial of Service) vulnerability. The vulnerability was identified in the mask! method, which used a regular expression that was susceptible to exponential backtracking when processing malformed input. This could have led to a denial of service condition when the library was used to process user-supplied IP addresses.
📂 Report JSON File: 1485717
@hackeronereports
🎯 New Report #1487889: ReDoS in Psych
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-21
Disclosed: 2025-07-08 22:56:51
📝 Summary: The Psych library in Ruby was found to have a ReDoS (Regular Expression Denial of Service) vulnerability in the parsing of time strings. The vulnerability was identified in the regular expression used to extract date and time information from the input string. The regular expression was susceptible to catastrophic backtracking, which could lead to significant performance degradation when parsing malformed input.
📂 Report JSON File: 1487889
@hackeronereports
🎯 New Report #3242087: Arbitrary File Read via file:// Protocol in cURL
🔺Severity: Critical
👽 Reporter: mr tufan
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-09
Disclosed: 2025-07-09 07:23:25
📝 Summary: null
📂 Report JSON File: 3242087
@hackeronereports
⚠️ The new version of the HackerOne report monitoring bot has been updated:

1️⃣. Initial reports are now stored as JSON files on GitHub.
2️⃣. From now on, "not-applicable" reports will not be displayed in the channel.
3️⃣. The report status, which can be closed as "resolved" or "informative," will be shown.
🔥Good luck crushing it in your bug hunts!

@hackeronereports