HackerOne Disclosed Reports - 2026-07-29

0 Replies, 12 Views

Logo
Medium
resolved

HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)


Bug reported by vnyuh was disclosed at July 30, 2026, 2:09 am   |   Exploiting Incorrectly Configured SSL/TLS

A vulnerability was identified in Node.js where HTTPS Agent TLS session reuse skipped hostname verification across identity policies, which was an incomplete fix for CVE-2026-48934. This affected Node.js versions 22.x, 24.x, and 26.x.


Logo
High
resolved

GitHub scoped user to server tokens can escape their installation


Bug reported by ahacker1 was disclosed at July 29, 2026, 11:35 pm   |   Improper Access Control - Generic

An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server was discovered. The vulnerability allowed an authenticated attacker to access private repositories outside the intended installation scope, which could have included write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26.


Logo
High
resolved

Permission Model: --allow-fs-read/--allow-fs-write radix-tree prefix-boundary over-grant


Bug reported by Jiyong Yang was disclosed at July 29, 2026, 11:00 pm   |   Improper Access Control - Generic

A flaw was discovered in the Node.js Permission Model's enforcement of filesystem access control. The vulnerability could allow an attacker granted access to one path to read from or write to paths outside the intended filesystem allowlist, due to issues with the radix-tree prefix-boundary handling. This affected Node.js versions in the main, 22.x, 24.x, and 26.x branches.


Logo
High
resolved

`exportReportPdf` mutation shows internal Activity


Bug reported by kimingi was disclosed at July 29, 2026, 3:01 pm   |  

A vulnerability was identified in the PDF export path for disclosed reports. When a report was exported to PDF, the export pipeline did not apply the same visibility and authorization scoping that governs the normal report view. The root cause was that PDF generation assembled report content from the underlying timeline without re-checking each activity against the requester's permission level. The issue was promptly fixed by enforcing the same per-activity visibility checks and disclosure-level scoping along the export path.


Logo
Medium
resolved

HTTPS Agent PFX object-array key collision allows mTLS client identity reuse across different per-request certificates


Bug reported by was disclosed at July 29, 2026, 2:45 pm   |   Improper Authentication - Generic

A flaw in Node.js HTTPS Agent connection reuse was discovered that could cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affected Node.js versions 26.x, 24.x, and 22.x.


Logo
Low
resolved

Permission Model Bypass: `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`


Bug reported by Sir bugs was disclosed at July 29, 2026, 2:16 pm   |   Improper Access Control - Generic

A flaw in Node.js Permission Model enforcement was discovered that allowed `trace_events.createTracing().enable()` to write trace logs outside of the `--allow-fs-write` setting. This vulnerability affected Node.js versions 22.x, 24.x, and 26.x.


Logo
High
resolved

Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)


Bug reported by KT was disclosed at July 29, 2026, 1:48 am   |   Server-Side Request Forgery (SSRF)

An SSRF vulnerability was discovered in Rocket.Chat version 7.13.2 that was caused by a DNS rebinding attack. The vulnerability allowed an attacker to bypass a security check and access internal hosts on the same network as the Rocket.Chat server. The vulnerability was present in the SMS integration feature that used the `checkUrlForSsrf` function, which was bypassed by the DNS rebinding attack.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)