![]() |
|
HackerOne Disclosed Reports - 2026-09-14 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-09-14 (/Thread-HackerOne-Disclosed-Reports-2026-09-14) |
HackerOne disclosed reports - 2026-09-14 - hashXploiter - 09-15-2026
High
resolved HTTP Request Smuggling via Unsanitized Hop-by-Hop HeadersBug reported by Quan Le was disclosed at September 14, 2026, 4:57 am | Improper Access Control - Generic The vulnerability allowed forwarding of HTTP/1 h2c upgrade requests to upstream servers, bypassing request-level filters applied by the proxy. The issue was addressed in Pingora version 0.9.0, which restricted HTTP/1 upgrades to WebSocket by default. |