![]() |
|
HackerOne Disclosed Reports - 2026-10-04 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-10-04 (/Thread-HackerOne-Disclosed-Reports-2026-10-04) |
HackerOne disclosed reports - 2026-10-04 - hashXploiter - 10-05-2026
High
resolved Client-Side Denial of Service (DoS) via Memory Exhaustion on Password Reset EndpointBug reported by Dipesh Pokhrel was disclosed at October 5, 2026, 2:23 am | Uncontrolled Resource Consumption A client-side denial of service vulnerability was identified on a password reset endpoint. When the endpoint was accessed by an authenticated user, the browser automatically generated thousands of requests without user interaction, resulting in rapid memory exhaustion. The browser became unresponsive and crashed within minutes as memory usage continuously increased.
Medium
resolved libmariadb ( mariadb-connector-c ): stack overflow via server-controlled field->length in prepared-statement codecBug reported by Yalguun Tumenkhuu was disclosed at October 4, 2026, 7:44 am | Stack Overflow A stack overflow vulnerability was discovered in the prepared-statement codec of the database connector library. The vulnerability allowed a malicious database server or network attacker to crash client applications by sending specially crafted column-definition packets with excessively large field-length values. When clients attempted to fetch query results, the field-length value was read without validation and passed directly to a stack allocation function, causing immediate process termination. The issue affected multiple versions of the connector library and downstream applications using prepared statements for database queries. |