HackerOne Disclosed Reports - 2026-09-02

0 Replies, 17 Views

Logo
Medium
resolved

CVE-2026-19931: Negotiate ambient user conn reuse


Bug reported by Martin Dukek was disclosed at September 3, 2026, 6:09 am   |   Authentication Bypass by Primary Weakness


Logo
Low
resolved

CVE-2026-80231: native CA store conn reuse


Bug reported by Anteater was disclosed at September 3, 2026, 6:08 am   |  


Logo
Low
resolved

CVE-2026-13608: OpenLDAP SASL authentication bypass


Bug reported by Eunsoo Kim was disclosed at September 3, 2026, 12:35 am   |   Authentication Bypass by Primary Weakness

A vulnerability was discovered in the OpenLDAP SASL authentication mechanism in libcurl. The vulnerability could allow a malicious LDAP server to bypass SASL authentication, potentially allowing the injection of arbitrary LDAP results. The vulnerable code has been present since the OpenLDAP SASL support was introduced and was unchanged in the current release.


Logo
Medium
resolved

CVE-2026-80256: wcurl backslash bypass


Bug reported by 1rhino2 was disclosed at September 2, 2026, 9:19 am   |   Path Traversal: '.../...//'

A vulnerability was discovered in the wcurl script of the curl project. The vulnerability allowed an attacker-controlled URL to create a new file outside the directory chosen by a Windows user, subject to the user's filesystem permissions and the target not already existing. The vulnerability was caused by the get_url_filename() function in the wcurl script, which protected percent-encoded characters but left a literal backslash unchanged before it became the automatic output filename. The vulnerability was reproduced on native Windows 10 build 19045 using the current official curl 8.21.0_7 x64 archive.


Logo
High
resolved

SSRF via URL Parser Differential in `normalize_request_url` (wlc)


Bug reported by Dark River was disclosed at September 2, 2026, 7:49 am   |   Server-Side Request Forgery (SSRF)

The Weblate CLI client (wlc) was found to be vulnerable to Server-Side Request Forgery (SSRF) due to a differential in URL parsing between the urllib and urllib3 libraries. The vulnerability was present in the normalize_request_url function, which was meant to validate that outgoing API requests stayed on the configured server's origin. However, the actual HTTP request was dispatched by the requests library, which relied on urllib3's URL parser. This allowed an attacker-controlled server to return a crafted URL that passed the origin validation but resulted in the client making a request to an arbitrary host.


Logo
Low
resolved

CVE-2026-18924: HTTP/2 server push UAF


Bug reported by was disclosed at September 2, 2026, 7:44 am   |   Use After Free

A vulnerability was discovered in libcurl versions 8.21.0 and later, where a use-after-free issue could occur in the HTTP/2 server push functionality. The vulnerability was caused by the fact that when a pushed transfer ends, the connection's pool is not properly handled, leading to the freed connection data being accessed later. The vulnerability was reproducible in a standalone program using the affected libcurl versions.


Logo
High
resolved

connect.8x8.com: Automation Builder - Input Validation Issue in Workflow Step Outputs


Bug reported by KauĆ£ Ferreira was disclosed at September 2, 2026, 12:03 am   |   External Control of Critical State Data

An input validation issue was reported in the 8x8 Connect Automation Builder's API where workflow step output field names were not validated against reserved context variable names. The issue was addressed by implementing validation to reject reserved field names at workflow creation.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-09-02 - by hashXploiter - Yesterday, 12:30 PM



Users browsing this thread: 1 Guest(s)