HackerOne Bug Bounty Disclosure: toctou-race-condition-in-http-connection-reuse-leads-to-certificate-validation-bypass–xrey

Company Name:
curl

Company HackerOne URL:
https://hackerone.com/curl

Submitted By:
0xrey

Link to Submitters Profile:
https://hackerone.com/0xrey

Report Title:
TOCTOU Race Condition in HTTP/2 Connection Reuse Leads to Certificate Validation Bypass

Report Link:
https://hackerone.com/reports/3335085

Date Submitted:
11 September 2025

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.