Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2025-10-06
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
Medium
resolved

Exceeding the limit of Workspaces via Race Condition


Bug reported by Ali Abbas was disclosed at October 6, 2025, 9:17 am   |   Business Logic Errors

The reporter discovered a race condition vulnerability in backend.singlestore.com that allowed free-tier users to bypass the 5-workspace limit by sending multiple simultaneous CreateWorkspace requests. This issue was patched by SingleStore as of October 3rd, 2025.