Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2026-10-04
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
High
resolved

Client-Side Denial of Service (DoS) via Memory Exhaustion on Password Reset Endpoint


Bug reported by Dipesh Pokhrel was disclosed at October 5, 2026, 2:23 am   |   Uncontrolled Resource Consumption

A client-side denial of service vulnerability was identified on a password reset endpoint. When the endpoint was accessed by an authenticated user, the browser automatically generated thousands of requests without user interaction, resulting in rapid memory exhaustion. The browser became unresponsive and crashed within minutes as memory usage continuously increased.


Logo
Medium
resolved

libmariadb ( mariadb-connector-c ): stack overflow via server-controlled field->length in prepared-statement codec


Bug reported by Yalguun Tumenkhuu was disclosed at October 4, 2026, 7:44 am   |   Stack Overflow

A stack overflow vulnerability was discovered in the prepared-statement codec of the database connector library. The vulnerability allowed a malicious database server or network attacker to crash client applications by sending specially crafted column-definition packets with excessively large field-length values. When clients attempted to fetch query results, the field-length value was read without validation and passed directly to a stack allocation function, causing immediate process termination. The issue affected multiple versions of the connector library and downstream applications using prepared statements for database queries.