Hackerone Reports
227 subscribers
743 links
Last Check 2026-09-20 04:45:01
Download Telegram
🎯 New Report #2861797: curl mishandles ` ` sequences in HTTP responses leading to CRLF confusions, Headers and Cookies Injection
🔺Severity: null
👽 Reporter: mdakh404
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-23
Disclosed: 2025-07-07 10:17:41
📝 Summary: null
📂 Report JSON File: 2861797
@hackeronereports
🎯 New Report #2864414: Arbitrary File Deletion Vulnerability in curl Source Code via os.unlink()
🔺Severity: High
👽 Reporter: aadityaathehacker
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
Disclosed: 2025-07-07 10:17:31
📝 Summary: null
📂 Report JSON File: 2864414
@hackeronereports
🎯 New Report #2864859: -H with space prefix leads to previous header injection when used with --proxy
🔺Severity: Medium
👽 Reporter: spongebhav
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
Disclosed: 2025-07-07 10:17:20
📝 Summary: null
📂 Report JSON File: 2864859
@hackeronereports
🎯 New Report #2904921: OS Command Injection (subprocess Module Usage)
🔺Severity: Low
👽 Reporter: bulter
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-17
Disclosed: 2025-07-07 10:17:09
📝 Summary: null
📂 Report JSON File: 2904921
@hackeronereports
🎯 New Report #2915426: Git repository found
🔺Severity: High
👽 Reporter: tefa
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-27
Disclosed: 2025-07-07 10:16:58
📝 Summary: null
📂 Report JSON File: 2915426
@hackeronereports
🎯 New Report #3238249: Integer Overflow Risk in HTTP/2 Proxy Window Size Calculations
🔺Severity: Medium
👽 Reporter: extramayoextracheeseextrafries
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-06
Disclosed: 2025-07-07 10:16:48
📝 Summary: null
📂 Report JSON File: 3238249
@hackeronereports
🎯 New Report #2402842: Information disclosure identified on IBM endpoint.
🔺Severity: Medium
👽 Reporter: devire
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2024-03-05
Disclosed: 2025-07-08 14:50:58
📝 Summary: The information disclosure vulnerability identified on an IBM endpoint was reported to IBM, analyzed, and remediated.
📂 Report JSON File: 2402842
@hackeronereports
🎯 New Report #3230359: CSRF at Network feature
🔺Severity: Medium
👽 Reporter: psfauzi
🛠 State: resolved
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-30
Disclosed: 2025-07-08 14:19:58
📝 Summary: A CSRF vulnerability was found in the network feature, where an attacker could change the Network Routing settings by sending a CSRF script to the victim.
📂 Report JSON File: 3230359
@hackeronereports
🎯 New Report #3241304: access notes without permission
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
Disclosed: 2025-07-08 19:54:37
📝 Summary: null
📂 Report JSON File: 3241304
@hackeronereports
🎯 New Report #3241308: Disclosure of email addresses
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
Disclosed: 2025-07-08 19:53:51
📝 Summary: null
📂 Report JSON File: 3241308
@hackeronereports
🎯 New Report #1485717: ReDoS in IPAddr
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-19
Disclosed: 2025-07-08 22:57:09
📝 Summary: The Ruby IPAddr library was found to be vulnerable to a ReDoS (Regular Expression Denial of Service) vulnerability. The vulnerability was identified in the mask! method, which used a regular expression that was susceptible to exponential backtracking when processing malformed input. This could have led to a denial of service condition when the library was used to process user-supplied IP addresses.
📂 Report JSON File: 1485717
@hackeronereports
🎯 New Report #1487889: ReDoS in Psych
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-21
Disclosed: 2025-07-08 22:56:51
📝 Summary: The Psych library in Ruby was found to have a ReDoS (Regular Expression Denial of Service) vulnerability in the parsing of time strings. The vulnerability was identified in the regular expression used to extract date and time information from the input string. The regular expression was susceptible to catastrophic backtracking, which could lead to significant performance degradation when parsing malformed input.
📂 Report JSON File: 1487889
@hackeronereports
🎯 New Report #3242087: Arbitrary File Read via file:// Protocol in cURL
🔺Severity: Critical
👽 Reporter: mr tufan
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-09
Disclosed: 2025-07-09 07:23:25
📝 Summary: null
📂 Report JSON File: 3242087
@hackeronereports
⚠️ The new version of the HackerOne report monitoring bot has been updated:

1️⃣. Initial reports are now stored as JSON files on GitHub.
2️⃣. From now on, "not-applicable" reports will not be displayed in the channel.
3️⃣. The report status, which can be closed as "resolved" or "informative," will be shown.
🔥Good luck crushing it in your bug hunts!

@hackeronereports
🎯 New Report #3099978: Leaked reused password for a few Khan Academy users
🔺Severity: High
👽 Reporter: a0xtrojan
🛠 State: resolved
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-04-18
Disclosed: 2025-07-12 10:31:05
📝 Summary: Leaked reused passwords for a few Khan Academy users were discovered on a Telegram bot. The exact source of the leaked data is unknown, but the volume of exposed information is substantial, including user emails and passwords.
📂 Report JSON File: 3099978
@hackeronereports
😱1
🎯 New Report #3181802: Reflected XSS in "Client Notes" Field
🔺Severity: Low
👽 Reporter: rishail01
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-06
Disclosed: 2025-07-13 16:47:10
📝 Summary: A reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" functionality under the Edit Client section. User input in the notes input field was not properly sanitized or encoded, allowing malicious JavaScript payloads to be reflected back in the application's HTML response upon submission. While this vulnerability was not directly exploitable by other users, it highlighted a potential entry point for more severe XSS vulnerabilities in the application.
📂 Report JSON File: 3181802
@hackeronereports
🎯 New Report #3131758: HashDoS in V8
🔺Severity: High
👽 Reporter: sharp edged
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-05-06
Disclosed: 2025-07-15 22:49:53
📝 Summary: The V8 release used in Node.js v24.0.0 changed how string hashes were computed using rapidhash. This implementation reintroduced the HashDoS vulnerability, where an attacker who could control the strings to be hashed could generate many hash collisions without knowing the hash-seed.
📂 Report JSON File: 3131758
@hackeronereports
🎯 New Report #3160912: Windows Device Names (CON, PRN, AUX) Bypass Path Traversal Protection in path.normalize()
🔺Severity: High
👽 Reporter: oblivionsage
⭐️ Reputation: 246
🛠 State: resolved
💼 Team: Node.js
💵 Bounty: null
🕐 Submitted: 2025-05-23
Disclosed: 2025-07-15 22:44:08
📝 Summary: An incomplete fix has been identified for a vulnerability affecting Windows device names in the path.normalize() function in Node.js. The vulnerability allows path traversal protection to be bypassed on devices such as CON, PRN, and AUX.
📂 Report JSON File: 3160912
@hackeronereports
🔥1
🎯 New Report #1577940: Banned user still has access to their deleted account via HackerOne's API using their API key
🔺Severity: Medium
👽 Reporter: mrmax4o4
⭐️ Reputation: 3165
🛠 State: resolved
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2022-05-22
Disclosed: 2025-07-14 20:50:35
📝 Summary: The user's banned account could still be accessed using their previously generated API token, allowing them to perform actions such as retrieving reports, balance, earnings, payouts, weaknesses, and program information. This vulnerability was discovered and exploited on a test account.
📂 Report JSON File: 1577940
@hackeronereports
🎯 New Report #3179850: exposure of personal IP address via email.
🔺Severity: null
👽 Reporter: micael1
⭐️ Reputation: 84
🛠 State: resolved
💼 Team: Weblate
💵 Bounty: null
🕐 Submitted: 2025-06-05
Disclosed: 2025-07-16 12:37:20
📝 Summary: The exposure of personal IP address through email was identified as a potential privacy concern. Email messages, even with TLS encryption, can pass through various servers that may store or record the content, including the user's IP address. This IP address can be considered personally identifiable information and may reveal information about the user's location, internet service provider, and device. It was recommended to avoid including raw IP addresses in outbound email messages and instead provide approximate location or prompt users to review login activity through a secure dashboard, in order to adhere to security principles such as least privilege and data minimization.
📂 Report JSON File: 3179850
@hackeronereports
🎯 New Report #3185205: Reflected XSS in "Cost Tracker" Notes Field
🔺Severity: Low
👽 Reporter: rishail01
⭐️ Reputation: 200
🛠 State: resolved
💼 Team: MainWP
💵 Bounty: 50
🕐 Submitted: 2025-06-10
Disclosed: 2025-07-17 09:08:50
📝 Summary: The reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field of the Cost Tracker section in MainWP (Version 5.4.0.11). Arbitrary user input in this field was reflected back and executed immediately upon saving, due to the lack of proper input sanitization and output encoding.
📂 Report JSON File: 3185205
@hackeronereports