bug bounty

HackerOne Bug Bounty Disclosure: application-level-dos-large-markdown-payload-in-reply-section-leading-to-resource-exhaustion-theteatoast

Company Name: Discourse Company HackerOne URL: https://hackerone.com/discourse Submitted By:theteatoastLink to Submitters Profile:https://hackerone.com/theteatoast Report Title:Application Level DoS - Large Markdown Payload...

HackerOne Bug Bounty Disclosure: path-traversal-vulnerability-in-nextcloud-tables-enables-arbitrary-file-exfiltration-of-any-files-supported-by-phpspreadsheet-library-daroo

Company Name: Nextcloud Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:darooLink to Submitters Profile:https://hackerone.com/daroo Report Title:Path Traversal Vulnerability in Nextcloud Tables Enables...

BugCrowd Bug Bounty Disclosure: P5 – internal IP Disclosure via Public DNS Record (blue.guest.hq.nasa.gov) – Theekshana_kusal

internal IP Disclosure via Public DNS Record (blue.guest.hq.nasa.gov) internal IP Disclosure via Public DNS Record (blue.guest.hq.nasa.gov) Researcher: Theekshana_kusal Engagement: National...

BugCrowd Bug Bounty Disclosure: P4 – open redirect vulnerability occurring at https://keycloak.shared-services.staging.appdat.jsc.nasa.gov/ – uko3211

open redirect vulnerability occurring at https://keycloak.shared-services.staging.appdat.jsc.nasa.gov/ open redirect vulnerability occurring at https://keycloak.shared-services.staging.appdat.jsc.nasa.gov/ Researcher: uko3211 Engagement: National Aeronautics and Space Administration...

BugCrowd Bug Bounty Disclosure: P4 – Publicly editable Google Slides linked from nasa.gov enables unauthorized content modification (content integrity & brand abuse risk – Epenetus-Matias-Putra

Publicly editable Google Slides linked from nasa.gov enables unauthorized content modification (content integrity & brand abuse risk Publicly editable Google...

HackerOne Bug Bounty Disclosure: samesite-restrictions-are-lifted-and-samesite-strict-cookie-are-being-sent-mingijung

Company Name: Brave Software Company HackerOne URL: https://hackerone.com/brave Submitted By:mingijungLink to Submitters Profile:https://hackerone.com/mingijung Report Title:SameSite restrictions are lifted, and SameSite:Strict...

HackerOne Bug Bounty Disclosure: apple-sectrust-legacy-path-accepts-untrusted-certificates-on-pre-macos-ios-when-built-with-use-apple-sectrust-giant-anteater

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:giant_anteaterLink to Submitters Profile:https://hackerone.com/giant_anteater Report Title:Apple SecTrust legacy path accepts untrusted certificates...

HackerOne Bug Bounty Disclosure: dns-rebinding-ssrf-in-burp-suite-mcp-server-enables-internal-network-access-via-send-hxxp-request-tool-farmer

Company Name: PortSwigger Web Security Company HackerOne URL: https://hackerone.com/portswigger Submitted By:farmerLink to Submitters Profile:https://hackerone.com/farmer Report Title:DNS Rebinding SSRF in Burp...

HackerOne Bug Bounty Disclosure: openssl-backend-x-peer-certificate-not-freed-in-ossl-get-channel-binding-causes-per-request-memory-leak-dos-risk-for-long-lived-clients-giant-anteater

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:giant_anteaterLink to Submitters Profile:https://hackerone.com/giant_anteater Report Title:OpenSSL backend: X509 peer certificate not freed...

HackerOne Bug Bounty Disclosure: csrf-vulnerability-allows-disabling-gmail-contacts-link-for-user-referrals-khaledx

Company Name: Insightly Company HackerOne URL: https://hackerone.com/insightly Submitted By:khaledxLink to Submitters Profile:https://hackerone.com/khaledx Report Title:CSRF vulnerability allows disabling Gmail contacts link...

HackerOne Bug Bounty Disclosure: int-overflow-in-krb-read-data-leads-to-possible-massive-recv-write-smiliesandco

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:smiliesandcoLink to Submitters Profile:https://hackerone.com/smiliesandco Report Title:int overflow in krb5_read_data() leads to (possible)...

HackerOne Bug Bounty Disclosure: url-scheme-validation-bypass-in-shopify-mobile-app-allows-javascript-execution-fr-via

Company Name: Shopify Company HackerOne URL: https://hackerone.com/shopify Submitted By:fr4viaLink to Submitters Profile:https://hackerone.com/fr4via Report Title:URL Scheme Validation Bypass in Shopify Mobile...