HackerOne Disclosed Reports - 2026-09-30

0 Replies, 7 Views

Logo
Critical
resolved

IDOR allows user to access report details via reference.json endpoint


Bug reported by sm41ldrag0n_mbbank was disclosed at October 1, 2026, 1:27 am   |   Insecure Direct Object Reference (IDOR)

An information disclosure vulnerability was identified in a report details endpoint that allowed unauthorized users to access private report information. Despite the endpoint returning an access-denied error response, sensitive report details were inadvertently exposed in the error message body. The vulnerability was discovered through testing with standard user accounts and has since been fixed. No evidence of exploitation was found.


Logo
Medium
resolved

SSRF via User-Controlled Push proxyServer in Notifications Push Registration


Bug reported by _dha was disclosed at September 30, 2026, 3:43 pm   |   Server-Side Request Forgery (SSRF)

A server-side request forgery vulnerability was discovered in the notifications application version 5.0.0. An authenticated user with low privileges could register a push device with an attacker-controlled proxy server address through the push registration endpoint. When a notification was triggered for that user, the backend performed an outbound POST request to the attacker-specified proxy server address, allowing the backend to make HTTP requests to arbitrary destinations including internal services.


Logo
Medium
resolved

Connector/J: malicious server crashes client JVM via unbounded result-set field-count allocation in ClientMessage.readPacket


Bug reported by Yalguun Tumenkhuu was disclosed at September 30, 2026, 8:00 am   |   Uncontrolled Resource Consumption

MariaDB Connector/J was found to have an unbounded result-set field-count allocation vulnerability. When parsing result-set responses, the driver read the column count directly from the wire and used it to size a Java array without validation. A malicious server was able to declare an extremely large field count in a small packet, causing the client JVM to attempt a multi-gigabyte memory allocation and crash with OutOfMemoryError. The crash affected the entire JVM process, taking down all pooled connections and application threads. The vulnerability could be triggered at connection time during driver initialization, before any legitimate query execution and without requiring valid credentials. The driver's default plaintext mode made it susceptible to network-level attacks.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)