Bug Bounty

HackerOne Bug Bounty Disclosure: apple-sectrust-legacy-path-accepts-untrusted-certificates-on-pre-macos-ios-when-built-with-use-apple-sectrust-giant-anteater

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:giant_anteaterLink to Submitters Profile:https://hackerone.com/giant_anteater Report Title:Apple SecTrust legacy path accepts untrusted certificates...

HackerOne Bug Bounty Disclosure: openssl-backend-x-peer-certificate-not-freed-in-ossl-get-channel-binding-causes-per-request-memory-leak-dos-risk-for-long-lived-clients-giant-anteater

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:giant_anteaterLink to Submitters Profile:https://hackerone.com/giant_anteater Report Title:OpenSSL backend: X509 peer certificate not freed...

HackerOne Bug Bounty Disclosure: dns-rebinding-ssrf-in-burp-suite-mcp-server-enables-internal-network-access-via-send-hxxp-request-tool-farmer

Company Name: PortSwigger Web Security Company HackerOne URL: https://hackerone.com/portswigger Submitted By:farmerLink to Submitters Profile:https://hackerone.com/farmer Report Title:DNS Rebinding SSRF in Burp...

HackerOne Bug Bounty Disclosure: csrf-vulnerability-allows-disabling-gmail-contacts-link-for-user-referrals-khaledx

Company Name: Insightly Company HackerOne URL: https://hackerone.com/insightly Submitted By:khaledxLink to Submitters Profile:https://hackerone.com/khaledx Report Title:CSRF vulnerability allows disabling Gmail contacts link...

HackerOne Bug Bounty Disclosure: int-overflow-in-krb-read-data-leads-to-possible-massive-recv-write-smiliesandco

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:smiliesandcoLink to Submitters Profile:https://hackerone.com/smiliesandco Report Title:int overflow in krb5_read_data() leads to (possible)...

HackerOne Bug Bounty Disclosure: url-scheme-validation-bypass-in-shopify-mobile-app-allows-javascript-execution-fr-via

Company Name: Shopify Company HackerOne URL: https://hackerone.com/shopify Submitted By:fr4viaLink to Submitters Profile:https://hackerone.com/fr4via Report Title:URL Scheme Validation Bypass in Shopify Mobile...

HackerOne Bug Bounty Disclosure: graphql-introspection-enabled-on-shopify-api-endpoint-intended-behavior-ahmednasr

Company Name: Shopify Company HackerOne URL: https://hackerone.com/shopify Submitted By:ahmednasr1Link to Submitters Profile:https://hackerone.com/ahmednasr1 Report Title:GraphQL Introspection Enabled on Shopify API Endpoint...

HackerOne Bug Bounty Disclosure: stored-xss-on-tiktok-s-backend-leads-to-the-leakage-of-highly-sensitive-administrator-data-cookies-api-keys-internal-paths-emails-phone-numbers-ahmed-xyz

Company Name: TikTok Company HackerOne URL: https://hackerone.com/tiktok Submitted By:ahmed_xyzLink to Submitters Profile:https://hackerone.com/ahmed_xyz Report Title:Stored XSS on TikTok's backend leads to...

HackerOne Bug Bounty Disclosure: toctou-race-condition-in-http-connection-reuse-leads-to-certificate-validation-bypass–xrey

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:0xreyLink to Submitters Profile:https://hackerone.com/0xrey Report Title:TOCTOU Race Condition in HTTP/2 Connection Reuse...

HackerOne Bug Bounty Disclosure: chained-broken-access-control-in-tiktok-live-backstage-enables-full-control-of-public-leaderboard-activities-eneri

Company Name: TikTok Company HackerOne URL: https://hackerone.com/tiktok Submitted By:eneriLink to Submitters Profile:https://hackerone.com/eneri Report Title:Chained Broken Access Control in TikTok Live...

BugCrowd Bug Bounty Disclosure: P5 – Reflected Cross-Site Scripting (XSS) on www.nasa.gov/search/search.jsp – madhu873

Reflected Cross-Site Scripting (XSS) on www.nasa.gov/search/search.jsp Reflected Cross-Site Scripting (XSS) on www.nasa.gov/search/search.jsp Researcher: madhu873 Engagement: National Aeronautics and Space Administration...