![]() |
|
HackerOne Disclosed Reports - 2026-06-24 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-06-24 (/Thread-HackerOne-Disclosed-Reports-2026-06-24) |
HackerOne disclosed reports - 2026-06-24 - hashXploiter - 06-25-2026
Low
resolved HTTP Response Queue Poisoning via TOCTOU Race Condition in `http.Agent`Bug reported by 陳昱昇 was disclosed at June 25, 2026, 5:03 am | Time-of-check Time-of-use (TOCTOU) Race Condition
Low
resolved Unix domain socket server bypasses --permission network restrictions (incomplete CVE-2026-21636 fix)Bug reported by Vitaly was disclosed at June 25, 2026, 5:03 am | Improper Access Control - Generic
High
resolved Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatBug reported by Tasos Meletlidis was disclosed at June 25, 2026, 5:02 am | Improper Handling of Unicode Encoding
Medium
resolved Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matchingBug reported by Tasos Meletlidis was disclosed at June 25, 2026, 5:01 am | Improper Access Control - Generic
Medium
resolved TLS host identity verification bypass via session reuse with different servername leads to unauthorized connectionsBug reported by 3d7omb was disclosed at June 25, 2026, 5:01 am | Exploiting Incorrectly Configured SSL/TLS
Low
resolved Permission Model bypass via FileHandle.utimes() in the promises APIBug reported by Muhammad Daffa was disclosed at June 25, 2026, 5:00 am | Incorrect Default Permissions
Medium
resolved Proxy credentials leaked in ERR_PROXY_TUNNEL error messageBug reported by Ali Saifeldin was disclosed at June 25, 2026, 5:00 am | Privacy Violation
Medium
resolved Unbounded memory growth in `node:http2` clients via attacker-controlled ORIGIN framesBug reported by kingsd was disclosed at June 25, 2026, 4:59 am | Uncontrolled Resource Consumption
Medium
resolved Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindingsBug reported by Tasos Meletlidis was disclosed at June 25, 2026, 4:59 am | Improper Access Control - Generic
High
resolved Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (DoS)Bug reported by Erichen was disclosed at June 25, 2026, 4:58 am | Integer Overflow
Low
resolved CVE-2026-11564: Native CA trust persistBug reported by Daniel Stenberg was disclosed at June 24, 2026, 8:30 am | A vulnerability was discovered in the libcurl library where a native CA trust could persist after an easy handle switches to custom CA material. The vulnerability was found to affect builds of libcurl that enable the native CA trust feature. The issue stemmed from the fact that the library did not properly reset the native CA trust state when custom CA options were set, allowing the previously enabled native trust to remain active. This could lead to a potential trust policy bypass, where the library would continue to trust certificates from the native platform store even after the application had configured custom CA material.
Low
resolved CVE-2026-12064: proto-default skips SSH verificationBug reported by alienowo was disclosed at June 24, 2026, 8:29 am | Improper Certificate Validation
Low
resolved CVE-2026-11586: WS Auto-PONG memory exhaustionBug reported by evergarden1123 was disclosed at June 24, 2026, 8:29 am | Allocation of Resources Without Limits or Throttling
Low
resolved CVE-2026-11352: QUIC zero-length UDP datagrams busy-loopBug reported by vectorqueue was disclosed at June 24, 2026, 8:29 am | Uncontrolled Resource Consumption
Low
resolved CVE-2026-10536: HTTP/2 stream-dependency tree UAFBug reported by Anteater was disclosed at June 24, 2026, 8:28 am | Buffer Over-read
Low
resolved CVE-2026-8924: trailing dot domain super cookieBug reported by VEGA was disclosed at June 24, 2026, 8:28 am | Use of Incorrectly-Resolved Name or Reference
Low
resolved CVE-2026-9546: sending old refererBug reported by renjian was disclosed at June 24, 2026, 8:27 am | Use After Free
Medium
resolved CVE-2026-9079: stale proxy password leakBug reported by Keenan was disclosed at June 24, 2026, 8:26 am | Information Disclosure
Low
resolved CVE-2026-9080: UAF after pause in socket callbackBug reported by Anteater was disclosed at June 24, 2026, 8:25 am | Use After Free
Low
resolved CVE-2026-8286: wrong STARTTLS connection reuseBug reported by Daniel Stenberg was disclosed at June 24, 2026, 8:25 am | A vulnerability was found in the Curl library that allowed a plain-text connection to reuse an existing SSL-upgraded connection without verifying the SSL configuration. This could lead to a man-in-the-middle attack if an attacker was able to intercept the initial STARTTLS upgrade. The issue was caused by the lack of a protocol-specific check for the SSL configuration when reusing a connection.
Low
resolved CVE-2026-8932: incomplete mTLS config matching in conn reuseBug reported by Anteater was disclosed at June 24, 2026, 8:25 am | Business Logic Errors
Medium
resolved CVE-2026-8927: env-set cross-proxy Digest auth state leakBug reported by Ady Elouej was disclosed at June 24, 2026, 8:24 am | Improper Authentication - Generic
Medium
resolved CVE-2026-8925: SASL double-freeBug reported by Anteater was disclosed at June 24, 2026, 8:23 am | Double Free
Low
resolved CVE-2026-8926: password leak with netrc and user in URLBug reported by Anteater was disclosed at June 24, 2026, 8:23 am | Information Disclosure
Low
resolved CVE-2026-8458: wrong reuse for different servicesBug reported by was disclosed at June 24, 2026, 8:23 am | Authentication Bypass by Primary Weakness
Low
resolved Insufficient checks in the file path parameter allow writing to unauthorized directoriesBug reported by Axolot was disclosed at June 24, 2026, 7:03 am | External Control of File Name or Path A directory traversal vulnerability was identified in the file upload functionality. Authenticated users could write files to parent directories outside the intended upload location by manipulating the path parameter. The issue was classified as Low severity due to limited impact. The vulnerability has been remediated through proper path sanitization.
Low
resolved CVE-2026-9545: exposing HTTP/3 early dataBug reported by Eunsoo Kim was disclosed at June 24, 2026, 6:24 am | Improper Certificate Validation
Medium
resolved CVE-2026-11856: cross-origin Digest auth state leakBug reported by John was disclosed at June 24, 2026, 6:21 am | Information Exposure Through Sent Data
|