Month: August 2025

BugCrowd Bug Bounty Disclosure: P5 – Unauthenticated metadata disclosure of protected NASA flight reports and mission schedules via /ajax/activity – madhu873

Unauthenticated metadata disclosure of protected NASA flight reports and mission schedules via /ajax/activity Unauthenticated metadata disclosure of protected NASA flight...

HackerOne Bug Bounty Disclosure: insecure-websocket-usage-in-curl-documentation-and-examples-cwe-cleartext-transmission-of-sensitive-information-spectre

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:spectre-1Link to Submitters Profile:https://hackerone.com/spectre-1 Report Title:Insecure WebSocket Usage in curl Documentation and...

HackerOne Bug Bounty Disclosure: unsafe-global-ifs-modification-in-os-shell-script-enables-command-injection-and-parsing-flaws-cwe-cwe-spectre

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:spectre-1Link to Submitters Profile:https://hackerone.com/spectre-1 Report Title:Unsafe Global IFS Modification in OS400 Shell...

HackerOne Bug Bounty Disclosure: exposure-of-hard-coded-private-keys-and-credentials-in-curl-source-repository-cwe-spectre

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:spectre-1Link to Submitters Profile:https://hackerone.com/spectre-1 Report Title:Exposure of Hard-coded Private Keys and Credentials...

HackerOne Bug Bounty Disclosure: account-repository-takeover-via-abandoned-github-username-in-curl-s-href-extractor-c-ks-karem

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:ks_karem77Link to Submitters Profile:https://hackerone.com/ks_karem77 Report Title:Account/Repository Takeover via Abandoned GitHub Username in...