HackerOne Disclosed Reports - 2025-10-06

0 Replies, 137 Views

Logo
Medium
resolved

Exceeding the limit of Workspaces via Race Condition


Bug reported by Ali Abbas was disclosed at October 6, 2025, 9:17 am   |   Business Logic Errors

The reporter discovered a race condition vulnerability in backend.singlestore.com that allowed free-tier users to bypass the 5-workspace limit by sending multiple simultaneous CreateWorkspace requests. This issue was patched by SingleStore as of October 3rd, 2025.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-10-06 - by hashXploiter - 10-07-2025, 12:30 PM



Users browsing this thread: 1 Guest(s)