resolved
IDOR allows user to access report details via reference.json endpoint
Bug reported by sm41ldrag0n_mbbank was disclosed at October 1, 2026, 1:27 am | Insecure Direct Object Reference (IDOR)
An information disclosure vulnerability was identified in a report details endpoint that allowed unauthorized users to access private report information. Despite the endpoint returning an access-denied error response, sensitive report details were inadvertently exposed in the error message body. The vulnerability was discovered through testing with standard user accounts and has since been fixed. No evidence of exploitation was found.
resolved
SSRF via User-Controlled Push proxyServer in Notifications Push Registration
Bug reported by _dha was disclosed at September 30, 2026, 3:43 pm | Server-Side Request Forgery (SSRF)
A server-side request forgery vulnerability was discovered in the notifications application version 5.0.0. An authenticated user with low privileges could register a push device with an attacker-controlled proxy server address through the push registration endpoint. When a notification was triggered for that user, the backend performed an outbound POST request to the attacker-specified proxy server address, allowing the backend to make HTTP requests to arbitrary destinations including internal services.
resolved
Connector/J: malicious server crashes client JVM via unbounded result-set field-count allocation in ClientMessage.readPacket
Bug reported by Yalguun Tumenkhuu was disclosed at September 30, 2026, 8:00 am | Uncontrolled Resource Consumption
MariaDB Connector/J was found to have an unbounded result-set field-count allocation vulnerability. When parsing result-set responses, the driver read the column count directly from the wire and used it to size a Java array without validation. A malicious server was able to declare an extremely large field count in a small packet, causing the client JVM to attempt a multi-gigabyte memory allocation and crash with OutOfMemoryError. The crash affected the entire JVM process, taking down all pooled connections and application threads. The vulnerability could be triggered at connection time during driver initialization, before any legitimate query execution and without requiring valid credentials. The driver's default plaintext mode made it susceptible to network-level attacks.