<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Dark C0d3rs - Research Papers/Vulnerability reports]]></title>
		<link>https://darkcoders.wiki/</link>
		<description><![CDATA[Dark C0d3rs - https://darkcoders.wiki]]></description>
		<pubDate>Tue, 22 Sep 2026 22:28:30 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-20]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-20</link>
			<pubDate>Mon, 21 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-20</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3599470' style='color: #4aa3ff;' target='new'>Improper input validation in emoji field leads to sidebar UI denial of service</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/yoyomiski?type=user' style='color: #4aa3ff;' target='new'> <strong> _dha</strong></a> was disclosed at September 20, 2026, 10:04 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Collectives app version 4.0.0 where the emoji field in the page emoji update endpoint did not properly validate user input. An attacker could have submitted an excessively long string including newline characters instead of a valid emoji, causing the sidebar layout to become broken. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3599470' style='color: #4aa3ff;' target='new'>Improper input validation in emoji field leads to sidebar UI denial of service</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/yoyomiski?type=user' style='color: #4aa3ff;' target='new'> <strong> _dha</strong></a> was disclosed at September 20, 2026, 10:04 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Collectives app version 4.0.0 where the emoji field in the page emoji update endpoint did not properly validate user input. An attacker could have submitted an excessively long string including newline characters instead of a valid emoji, causing the sidebar layout to become broken. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-18]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-18</link>
			<pubDate>Sat, 19 Sep 2026 07:00:02 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-18</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3770482' style='color: #4aa3ff;' target='new'>files_lock: a write-share collaborator can place a TYPE_TOKEN lock that permanently denies the file owner, survives share revocation and account delet</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/rz1027?type=user' style='color: #4aa3ff;' target='new'> <strong> rz1027</strong></a> was disclosed at September 18, 2026, 3:36 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in files_lock 33.0.4 on Nextcloud 33.0.3 that allowed a user with write-share permissions on a file to place a permanent lock on the file that could not be removed by the file owner or an administrator. The lock was stored in the database and persisted even after the collaborator's account was deleted or recreated. The only way to remove the lock was through direct database access, which was not documented in the application's administrative tools. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/wds9tsdw2rclypa3m596vwa57zq0/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/4020767' style='color: #4aa3ff;' target='new'>Unauthenticated API allows reading, writing to and deleting any user's private chat history on ████████</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/agusnicco?type=user' style='color: #4aa3ff;' target='new'> <strong> Juan Agustin Niccolini</strong></a> was disclosed at September 18, 2026, 6:04 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Misconfiguration</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An unauthenticated API was discovered that allowed reading, writing to, and deleting any user's private chat history on the organization's internal chatbot application. The API had no authentication mechanism in place, allowing an attacker to list all conversations, retrieve the complete message history of any conversation, create new conversations, and delete any conversation. The deletion of a conversation was incomplete, as the underlying messages remained retrievable even after the conversation was removed from the listing. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3770482' style='color: #4aa3ff;' target='new'>files_lock: a write-share collaborator can place a TYPE_TOKEN lock that permanently denies the file owner, survives share revocation and account delet</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/rz1027?type=user' style='color: #4aa3ff;' target='new'> <strong> rz1027</strong></a> was disclosed at September 18, 2026, 3:36 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in files_lock 33.0.4 on Nextcloud 33.0.3 that allowed a user with write-share permissions on a file to place a permanent lock on the file that could not be removed by the file owner or an administrator. The lock was stored in the database and persisted even after the collaborator's account was deleted or recreated. The only way to remove the lock was through direct database access, which was not documented in the application's administrative tools. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/wds9tsdw2rclypa3m596vwa57zq0/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/4020767' style='color: #4aa3ff;' target='new'>Unauthenticated API allows reading, writing to and deleting any user's private chat history on ████████</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/agusnicco?type=user' style='color: #4aa3ff;' target='new'> <strong> Juan Agustin Niccolini</strong></a> was disclosed at September 18, 2026, 6:04 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Misconfiguration</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An unauthenticated API was discovered that allowed reading, writing to, and deleting any user's private chat history on the organization's internal chatbot application. The API had no authentication mechanism in place, allowing an attacker to list all conversations, retrieve the complete message history of any conversation, create new conversations, and delete any conversation. The deletion of a conversation was incomplete, as the underlying messages remained retrievable even after the conversation was removed from the listing. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-17]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-17</link>
			<pubDate>Fri, 18 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-17</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/wds9tsdw2rclypa3m596vwa57zq0/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/4020767' style='color: #4aa3ff;' target='new'>Unauthenticated API allows reading, writing to and deleting any user's private chat history on ████████</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/agusnicco?type=user' style='color: #4aa3ff;' target='new'> <strong> Juan Agustin Niccolini</strong></a> was disclosed at September 18, 2026, 6:04 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Misconfiguration</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An unauthenticated API was discovered that allowed reading, writing to, and deleting any user's private chat history on the organization's internal chatbot application. The API had no authentication mechanism in place, allowing an attacker to list all conversations, retrieve the complete message history of any conversation, create new conversations, and delete any conversation. The deletion of a conversation was incomplete, as the underlying messages remained retrievable even after the conversation was removed from the listing. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/4mpaehke5u0ubioeqvys0hcesjle/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3522157' style='color: #4aa3ff;' target='new'>SSRF with bypass leads to client side hosting / vulnerabilities ( XSS and others )</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ferreiraklet_?type=user' style='color: #4aa3ff;' target='new'> <strong> Daniel Ferreira</strong></a> was disclosed at September 17, 2026, 10:54 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The web application was found to be vulnerable to server-side request forgery (SSRF). The SSRF vulnerability was discovered through testing with an HTTP interception proxy. The vulnerability allowed an attacker to make arbitrary HTTP requests from the server, which could potentially lead to unauthorized access or data exposure. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3683934' style='color: #4aa3ff;' target='new'>sign_multisig crashes monero-wallet-rpc on a malformed but decryptable multisig txset</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/helping_bro?type=user' style='color: #4aa3ff;' target='new'> <strong> 0xbro</strong></a> was disclosed at September 17, 2026, 5:45 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The vulnerability in `monero-wallet-rpc`'s `sign_multisig` function allowed a malformed but decryptable multisig transaction set to cause a process crash instead of returning an error. The issue was resolved in version 0.18.5.0. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3683886' style='color: #4aa3ff;' target='new'>Restricted ZMQ RPC bypasses HTTP restricted-mode resource checks</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/helping_bro?type=user' style='color: #4aa3ff;' target='new'> <strong> 0xbro</strong></a> was disclosed at September 17, 2026, 5:42 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The restricted ZMQ RPC in monerod did not enforce the same request restrictions as the restricted HTTP RPC. The ZMQ RPC relied primarily on a small method blocklist, allowing several allowed methods to accept requests that the restricted HTTP RPC explicitly rejected or capped. This issue was resolved in version 0.18.5.0. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3681690' style='color: #4aa3ff;' target='new'>ZMQ get_output_distribution duplicate amount DoS</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/helping_bro?type=user' style='color: #4aa3ff;' target='new'> <strong> 0xbro</strong></a> was disclosed at September 17, 2026, 5:38 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The ZMQ `get_output_distribution` RPC was vulnerable to a memory exhaustion denial-of-service attack. The method accepted an unbounded `amounts` array and returned a separate distribution for each entry, allowing a small request to expand into a very large response by repeatedly including the amount `0`. The issue was also reachable with `--restricted-zmq-rpc` because ZMQ lacked the stricter validation applied by restricted HTTP RPC. The vulnerability was resolved in You are not allowed to view links. <a href="https://darkcoders.wiki/member.php?action=register">Register</a> or <a href="https://darkcoders.wiki/member.php?action=login">Login</a> to view. and v0.18.5.0. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3301553' style='color: #4aa3ff;' target='new'>Cross-User Lock/Unlock via Absolute DAV Path</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x0doteth?type=user' style='color: #4aa3ff;' target='new'> <strong> Balvant Chavda</strong></a> was disclosed at September 17, 2026, 1:09 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the files_lock app for Nextcloud. The vulnerability allowed any authenticated user to lock or unlock files they did not own by targeting absolute WebDAV paths of other users. This was possible because the DAV plugin resolved files from the absolute request URI without verifying that the user ID path segment matched the authenticated session user. This enabled cross-user manual locks and lock token disclosure, which allowed unauthorized callers to remove token-based locks of other users. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3506873' style='color: #4aa3ff;' target='new'>Shared smart albums in the Photos app can expose files outside the album owner's configured source folders</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/suul?type=user' style='color: #4aa3ff;' target='new'> <strong> Joseph Semaan</strong></a> was disclosed at September 17, 2026, 10:48 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in a file manager component of a file sharing application. The vulnerability allowed an attacker to access files outside of the intended shared folder by configuring more permissive search paths than the victim intended. This resulted in unauthorized information disclosure, as the system used the attacker's configuration to determine the search scope in the victim's folder. The vulnerability was caused by insufficient validation of the search paths provided by the attacker. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3674940' style='color: #4aa3ff;' target='new'>Critical broken access control: API-only delegated admin can enumerate all Team Folders and grant access to arbitrary groups</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/qloo?type=user' style='color: #4aa3ff;' target='new'> <strong> qloo</strong></a> was disclosed at September 17, 2026, 10:41 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A critical broken access control vulnerability was discovered in Nextcloud's Group Folders app. The vulnerability allowed an API/REST only delegated admin to bypass folder-level authorization and gain access to any Team Folder by abusing the POST /index.php/apps/groupfolders/folders/{id}/groups endpoint. This was possible because the folder IDs were predictable, allowing the attacker to enumerate all Team Folders and mass-assign their own group, resulting in full access to organization-wide data. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3610332' style='color: #4aa3ff;' target='new'>Approval app's file-freshness check can be bypassed by omitting the etag parameter, allowing approval of unreviewed file changes</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/vidang04?type=user' style='color: #4aa3ff;' target='new'> <strong> Dang Hung Vi</strong></a> was disclosed at September 17, 2026, 10:34 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the approval app's file-freshness check. The vulnerability allowed bypassing the check by omitting the etag parameter, enabling approval of unreviewed file changes. This broke the integrity of the approval process, as the approver could approve a different file state than the one they reviewed. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3599383' style='color: #4aa3ff;' target='new'>Arbitrary Board Preference Injection via Deck Config API</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/vidang04?type=user' style='color: #4aa3ff;' target='new'> <strong> Dang Hung Vi</strong></a> was disclosed at September 17, 2026, 10:20 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Deck Config API of the Nextcloud application that allowed authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating the user's ownership or permission to manage the referenced board. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3533697' style='color: #4aa3ff;' target='new'>Public collectives allow to create pages</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/yoyomiski?type=user' style='color: #4aa3ff;' target='new'> <strong> _dha</strong></a> was disclosed at September 17, 2026, 10:16 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Nextcloud Collectives application that allowed non-members accessing a public collective to create new pages through the backend API, bypassing the collective-level permission settings configured to restrict editing to administrators only. The vulnerability was caused by inconsistent permission enforcement between the user interface, collective settings, and backend API. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3303283' style='color: #4aa3ff;' target='new'>Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x0doteth?type=user' style='color: #4aa3ff;' target='new'> <strong> Balvant Chavda</strong></a> was disclosed at September 17, 2026, 6:22 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A blind SSRF vulnerability was discovered in the Circles app for Nextcloud. The vulnerability allowed unauthenticated users to force the server to fetch internal URLs, bypassing local-address protections in Nextcloud. The vulnerability was caused by the Circles app's signature verification process, which fetched an attacker-provided URL before trust was established. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3484601' style='color: #4aa3ff;' target='new'>Team membership information returned on API level based on ID</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/milou?type=user' style='color: #4aa3ff;' target='new'> <strong> Melanie</strong></a> was disclosed at September 17, 2026, 5:49 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Insecure Direct Object Reference (IDOR)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Nextcloud Circles app that allowed any authenticated user to access membership information for any circle and user combination, regardless of their authorization. The issue stemmed from a lack of permission checks in the affected service and request classes, as well as the public exposure of the vulnerable functionality through an API endpoint. This vulnerability could have led to the disclosure of sensitive organizational data, including private circle memberships, inheritance relationships, and user identification details. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/wds9tsdw2rclypa3m596vwa57zq0/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/4020767' style='color: #4aa3ff;' target='new'>Unauthenticated API allows reading, writing to and deleting any user's private chat history on ████████</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/agusnicco?type=user' style='color: #4aa3ff;' target='new'> <strong> Juan Agustin Niccolini</strong></a> was disclosed at September 18, 2026, 6:04 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Misconfiguration</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> An unauthenticated API was discovered that allowed reading, writing to, and deleting any user's private chat history on the organization's internal chatbot application. The API had no authentication mechanism in place, allowing an attacker to list all conversations, retrieve the complete message history of any conversation, create new conversations, and delete any conversation. The deletion of a conversation was incomplete, as the underlying messages remained retrievable even after the conversation was removed from the listing. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/4mpaehke5u0ubioeqvys0hcesjle/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3522157' style='color: #4aa3ff;' target='new'>SSRF with bypass leads to client side hosting / vulnerabilities ( XSS and others )</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/ferreiraklet_?type=user' style='color: #4aa3ff;' target='new'> <strong> Daniel Ferreira</strong></a> was disclosed at September 17, 2026, 10:54 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The web application was found to be vulnerable to server-side request forgery (SSRF). The SSRF vulnerability was discovered through testing with an HTTP interception proxy. The vulnerability allowed an attacker to make arbitrary HTTP requests from the server, which could potentially lead to unauthorized access or data exposure. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3683934' style='color: #4aa3ff;' target='new'>sign_multisig crashes monero-wallet-rpc on a malformed but decryptable multisig txset</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/helping_bro?type=user' style='color: #4aa3ff;' target='new'> <strong> 0xbro</strong></a> was disclosed at September 17, 2026, 5:45 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The vulnerability in `monero-wallet-rpc`'s `sign_multisig` function allowed a malformed but decryptable multisig transaction set to cause a process crash instead of returning an error. The issue was resolved in version 0.18.5.0. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3683886' style='color: #4aa3ff;' target='new'>Restricted ZMQ RPC bypasses HTTP restricted-mode resource checks</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/helping_bro?type=user' style='color: #4aa3ff;' target='new'> <strong> 0xbro</strong></a> was disclosed at September 17, 2026, 5:42 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The restricted ZMQ RPC in monerod did not enforce the same request restrictions as the restricted HTTP RPC. The ZMQ RPC relied primarily on a small method blocklist, allowing several allowed methods to accept requests that the restricted HTTP RPC explicitly rejected or capped. This issue was resolved in version 0.18.5.0. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3681690' style='color: #4aa3ff;' target='new'>ZMQ get_output_distribution duplicate amount DoS</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/helping_bro?type=user' style='color: #4aa3ff;' target='new'> <strong> 0xbro</strong></a> was disclosed at September 17, 2026, 5:38 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The ZMQ `get_output_distribution` RPC was vulnerable to a memory exhaustion denial-of-service attack. The method accepted an unbounded `amounts` array and returned a separate distribution for each entry, allowing a small request to expand into a very large response by repeatedly including the amount `0`. The issue was also reachable with `--restricted-zmq-rpc` because ZMQ lacked the stricter validation applied by restricted HTTP RPC. The vulnerability was resolved in You are not allowed to view links. <a href="https://darkcoders.wiki/member.php?action=register">Register</a> or <a href="https://darkcoders.wiki/member.php?action=login">Login</a> to view. and v0.18.5.0. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3301553' style='color: #4aa3ff;' target='new'>Cross-User Lock/Unlock via Absolute DAV Path</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x0doteth?type=user' style='color: #4aa3ff;' target='new'> <strong> Balvant Chavda</strong></a> was disclosed at September 17, 2026, 1:09 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the files_lock app for Nextcloud. The vulnerability allowed any authenticated user to lock or unlock files they did not own by targeting absolute WebDAV paths of other users. This was possible because the DAV plugin resolved files from the absolute request URI without verifying that the user ID path segment matched the authenticated session user. This enabled cross-user manual locks and lock token disclosure, which allowed unauthorized callers to remove token-based locks of other users. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3506873' style='color: #4aa3ff;' target='new'>Shared smart albums in the Photos app can expose files outside the album owner's configured source folders</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/suul?type=user' style='color: #4aa3ff;' target='new'> <strong> Joseph Semaan</strong></a> was disclosed at September 17, 2026, 10:48 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in a file manager component of a file sharing application. The vulnerability allowed an attacker to access files outside of the intended shared folder by configuring more permissive search paths than the victim intended. This resulted in unauthorized information disclosure, as the system used the attacker's configuration to determine the search scope in the victim's folder. The vulnerability was caused by insufficient validation of the search paths provided by the attacker. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3674940' style='color: #4aa3ff;' target='new'>Critical broken access control: API-only delegated admin can enumerate all Team Folders and grant access to arbitrary groups</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/qloo?type=user' style='color: #4aa3ff;' target='new'> <strong> qloo</strong></a> was disclosed at September 17, 2026, 10:41 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A critical broken access control vulnerability was discovered in Nextcloud's Group Folders app. The vulnerability allowed an API/REST only delegated admin to bypass folder-level authorization and gain access to any Team Folder by abusing the POST /index.php/apps/groupfolders/folders/{id}/groups endpoint. This was possible because the folder IDs were predictable, allowing the attacker to enumerate all Team Folders and mass-assign their own group, resulting in full access to organization-wide data. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3610332' style='color: #4aa3ff;' target='new'>Approval app's file-freshness check can be bypassed by omitting the etag parameter, allowing approval of unreviewed file changes</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/vidang04?type=user' style='color: #4aa3ff;' target='new'> <strong> Dang Hung Vi</strong></a> was disclosed at September 17, 2026, 10:34 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the approval app's file-freshness check. The vulnerability allowed bypassing the check by omitting the etag parameter, enabling approval of unreviewed file changes. This broke the integrity of the approval process, as the approver could approve a different file state than the one they reviewed. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3599383' style='color: #4aa3ff;' target='new'>Arbitrary Board Preference Injection via Deck Config API</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/vidang04?type=user' style='color: #4aa3ff;' target='new'> <strong> Dang Hung Vi</strong></a> was disclosed at September 17, 2026, 10:20 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Deck Config API of the Nextcloud application that allowed authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating the user's ownership or permission to manage the referenced board. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3533697' style='color: #4aa3ff;' target='new'>Public collectives allow to create pages</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/yoyomiski?type=user' style='color: #4aa3ff;' target='new'> <strong> _dha</strong></a> was disclosed at September 17, 2026, 10:16 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Nextcloud Collectives application that allowed non-members accessing a public collective to create new pages through the backend API, bypassing the collective-level permission settings configured to restrict editing to administrators only. The vulnerability was caused by inconsistent permission enforcement between the user interface, collective settings, and backend API. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3303283' style='color: #4aa3ff;' target='new'>Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x0doteth?type=user' style='color: #4aa3ff;' target='new'> <strong> Balvant Chavda</strong></a> was disclosed at September 17, 2026, 6:22 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A blind SSRF vulnerability was discovered in the Circles app for Nextcloud. The vulnerability allowed unauthenticated users to force the server to fetch internal URLs, bypassing local-address protections in Nextcloud. The vulnerability was caused by the Circles app's signature verification process, which fetched an attacker-provided URL before trust was established. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3484601' style='color: #4aa3ff;' target='new'>Team membership information returned on API level based on ID</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/milou?type=user' style='color: #4aa3ff;' target='new'> <strong> Melanie</strong></a> was disclosed at September 17, 2026, 5:49 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Insecure Direct Object Reference (IDOR)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Nextcloud Circles app that allowed any authenticated user to access membership information for any circle and user combination, regardless of their authorization. The issue stemmed from a lack of permission checks in the affected service and request classes, as well as the public exposure of the vulnerable functionality through an API endpoint. This vulnerability could have led to the disclosure of sensitive organizational data, including private circle memberships, inheritance relationships, and user identification details. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-16]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-16</link>
			<pubDate>Thu, 17 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-16</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3303283' style='color: #4aa3ff;' target='new'>Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x0doteth?type=user' style='color: #4aa3ff;' target='new'> <strong> Balvant Chavda</strong></a> was disclosed at September 17, 2026, 6:22 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A blind SSRF vulnerability was discovered in the Circles app for Nextcloud. The vulnerability allowed unauthenticated users to force the server to fetch internal URLs, bypassing local-address protections in Nextcloud. The vulnerability was caused by the Circles app's signature verification process, which fetched an attacker-provided URL before trust was established. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3484601' style='color: #4aa3ff;' target='new'>Team membership information returned on API level based on ID</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/milou?type=user' style='color: #4aa3ff;' target='new'> <strong> Melanie</strong></a> was disclosed at September 17, 2026, 5:49 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Insecure Direct Object Reference (IDOR)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Nextcloud Circles app that allowed any authenticated user to access membership information for any circle and user combination, regardless of their authorization. The issue stemmed from a lack of permission checks in the affected service and request classes, as well as the public exposure of the vulnerable functionality through an API endpoint. This vulnerability could have led to the disclosure of sensitive organizational data, including private circle memberships, inheritance relationships, and user identification details. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3633123' style='color: #4aa3ff;' target='new'> Incomplete Input Sanitization in CodeInterpreter install_packages Allows Command Injection via pip Flags</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/mistercloudsec?type=user' style='color: #4aa3ff;' target='new'> <strong> Sergio Garcia</strong></a> was disclosed at September 16, 2026, 8:57 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>OS Command Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The Bedrock AgentCore Python SDK was found to have an incomplete input sanitization vulnerability in the `install_packages()` method. The sanitization process failed to properly handle certain pip flags, such as `--index-url`, which allowed arbitrary command execution within the Code Interpreter sandbox. This vulnerability was discovered to affect all versions of the `bedrock-agentcore-sdk-python` up to at least v1.4.8. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3621588' style='color: #4aa3ff;' target='new'>Authenticated `unsigned_txset` change spoof lets a malicious hot wallet steal cold-signer change</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/usagirabbit?type=user' style='color: #4aa3ff;' target='new'> <strong> usagirabbit</strong></a> was disclosed at September 16, 2026, 9:16 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Monero's wallet code that allowed a malicious or compromised hot/watch-only wallet with the victim wallet's private view key to forge an authenticated unsigned transaction. The forged transaction included an attacker-controlled output that was presented as change, and the offline signer then reconstructed and signed that output as change. This resulted in a direct loss-of-funds issue, as the resulting output was attacker-spendable and not victim-spendable. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3303283' style='color: #4aa3ff;' target='new'>Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/0x0doteth?type=user' style='color: #4aa3ff;' target='new'> <strong> Balvant Chavda</strong></a> was disclosed at September 17, 2026, 6:22 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Server-Side Request Forgery (SSRF)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A blind SSRF vulnerability was discovered in the Circles app for Nextcloud. The vulnerability allowed unauthenticated users to force the server to fetch internal URLs, bypassing local-address protections in Nextcloud. The vulnerability was caused by the Circles app's signature verification process, which fetched an attacker-provided URL before trust was established. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3484601' style='color: #4aa3ff;' target='new'>Team membership information returned on API level based on ID</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/milou?type=user' style='color: #4aa3ff;' target='new'> <strong> Melanie</strong></a> was disclosed at September 17, 2026, 5:49 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Insecure Direct Object Reference (IDOR)</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Nextcloud Circles app that allowed any authenticated user to access membership information for any circle and user combination, regardless of their authorization. The issue stemmed from a lack of permission checks in the affected service and request classes, as well as the public exposure of the vulnerable functionality through an API endpoint. This vulnerability could have led to the disclosure of sensitive organizational data, including private circle memberships, inheritance relationships, and user identification details. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/fgfqam8gl7lzo8u8v0kiphkxfyt8/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3633123' style='color: #4aa3ff;' target='new'> Incomplete Input Sanitization in CodeInterpreter install_packages Allows Command Injection via pip Flags</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/mistercloudsec?type=user' style='color: #4aa3ff;' target='new'> <strong> Sergio Garcia</strong></a> was disclosed at September 16, 2026, 8:57 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>OS Command Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The Bedrock AgentCore Python SDK was found to have an incomplete input sanitization vulnerability in the `install_packages()` method. The sanitization process failed to properly handle certain pip flags, such as `--index-url`, which allowed arbitrary command execution within the Code Interpreter sandbox. This vulnerability was discovered to affect all versions of the `bedrock-agentcore-sdk-python` up to at least v1.4.8. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/007/731/55634f7fcd917725c7a5771cc6e7c9b4d5fe0c22_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3621588' style='color: #4aa3ff;' target='new'>Authenticated `unsigned_txset` change spoof lets a malicious hot wallet steal cold-signer change</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/usagirabbit?type=user' style='color: #4aa3ff;' target='new'> <strong> usagirabbit</strong></a> was disclosed at September 16, 2026, 9:16 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Monero's wallet code that allowed a malicious or compromised hot/watch-only wallet with the victim wallet's private view key to forge an authenticated unsigned transaction. The forged transaction included an attacker-controlled output that was presented as change, and the offline signer then reconstructed and signed that output as change. This resulted in a direct loss-of-funds issue, as the resulting output was attacker-spendable and not victim-spendable. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-15]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-15</link>
			<pubDate>Wed, 16 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-15</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/468/71eb3827ae9f2a388f27bd4b7eefd20bc3ac813c_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3874004' style='color: #4aa3ff;' target='new'> Incomplete fix for CVE-2022-23915: Mercurial argument injection in HgRepository.get_file() leads to command execution</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/mask0ff?type=user' style='color: #4aa3ff;' target='new'> <strong> Shawky </strong></a> was disclosed at September 15, 2026, 8:36 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>OS Command Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Weblate, a web-based translation tool. The vulnerability was caused by an incomplete fix for a previous issue (CVE-2022-23915). Weblate passed repository-controlled filenames to Mercurial without properly escaping them, allowing filenames beginning with "-" to be interpreted as command-line options. This could be abused by an authenticated user with project-scoped component-edit permission to inject Mercurial configuration and execute arbitrary commands as the Weblate service account. The vulnerability affected Weblate versions 4.11.1 through 2026.7.1 and was later assigned CVE-2026-86035. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/468/71eb3827ae9f2a388f27bd4b7eefd20bc3ac813c_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3874004' style='color: #4aa3ff;' target='new'> Incomplete fix for CVE-2022-23915: Mercurial argument injection in HgRepository.get_file() leads to command execution</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/mask0ff?type=user' style='color: #4aa3ff;' target='new'> <strong> Shawky </strong></a> was disclosed at September 15, 2026, 8:36 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>OS Command Injection</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Weblate, a web-based translation tool. The vulnerability was caused by an incomplete fix for a previous issue (CVE-2022-23915). Weblate passed repository-controlled filenames to Mercurial without properly escaping them, allowing filenames beginning with "-" to be interpreted as command-line options. This could be abused by an authenticated user with project-scoped component-edit permission to inject Mercurial configuration and execute arbitrary commands as the Weblate service account. The vulnerability affected Weblate versions 4.11.1 through 2026.7.1 and was later assigned CVE-2026-86035. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-14]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-14</link>
			<pubDate>Tue, 15 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-14</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/041/a819f0d518a4854df667be26210167805f38a6a4_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3622877' style='color: #4aa3ff;' target='new'>HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/1nsomnia1102?type=user' style='color: #4aa3ff;' target='new'> <strong> Quan Le</strong></a> was disclosed at September 14, 2026, 4:57 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The vulnerability allowed forwarding of HTTP/1 h2c upgrade requests to upstream servers, bypassing request-level filters applied by the proxy. The issue was addressed in Pingora version 0.9.0, which restricted HTTP/1 upgrades to WebSocket by default. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/041/a819f0d518a4854df667be26210167805f38a6a4_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3622877' style='color: #4aa3ff;' target='new'>HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/1nsomnia1102?type=user' style='color: #4aa3ff;' target='new'> <strong> Quan Le</strong></a> was disclosed at September 14, 2026, 4:57 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The vulnerability allowed forwarding of HTTP/1 h2c upgrade requests to upstream servers, bypassing request-level filters applied by the proxy. The issue was addressed in Pingora version 0.9.0, which restricted HTTP/1 upgrades to WebSocket by default. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-13]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-13</link>
			<pubDate>Mon, 14 Sep 2026 07:00:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-13</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/041/a819f0d518a4854df667be26210167805f38a6a4_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3622877' style='color: #4aa3ff;' target='new'>HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/1nsomnia1102?type=user' style='color: #4aa3ff;' target='new'> <strong> Quan Le</strong></a> was disclosed at September 14, 2026, 4:57 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>HTTP Request Smuggling</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/041/a819f0d518a4854df667be26210167805f38a6a4_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3622877' style='color: #4aa3ff;' target='new'>HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/1nsomnia1102?type=user' style='color: #4aa3ff;' target='new'> <strong> Quan Le</strong></a> was disclosed at September 14, 2026, 4:57 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>HTTP Request Smuggling</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-12]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-12</link>
			<pubDate>Sun, 13 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-12</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/022/5e2b46658c8b86bed62f574d8e1793f353cbbc63_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3994016' style='color: #4aa3ff;' target='new'>Action Text to_markdown: <code>/<pre> content escapes its delimiter, letting a stored body inject arbitrary Markdown</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/seoafoz?type=user' style='color: #4aa3ff;' target='new'> <strong> seoafoz</strong></a> was disclosed at September 12, 2026, 7:08 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Stored</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/000/022/5e2b46658c8b86bed62f574d8e1793f353cbbc63_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3994016' style='color: #4aa3ff;' target='new'>Action Text to_markdown: <code>/<pre> content escapes its delimiter, letting a stored body inject arbitrary Markdown</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/seoafoz?type=user' style='color: #4aa3ff;' target='new'> <strong> seoafoz</strong></a> was disclosed at September 12, 2026, 7:08 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Cross-site Scripting (XSS) - Stored</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-10]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-10</link>
			<pubDate>Fri, 11 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-10</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/800/6e575d0a9127b91e83833cf4a9e6be6e8b30cbc3_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3709605' style='color: #4aa3ff;' target='new'>Conflux-queued zero-length RELAY_END triggers heap out-of-bounds read</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/geeknik?type=user' style='color: #4aa3ff;' target='new'> <strong> Brian Carpenter</strong></a> was disclosed at September 10, 2026, 12:10 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Out-of-bounds Read</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Tor that could trigger a heap out-of-bounds read when a zero-length RELAY_END cell was processed on a non-open AP stream. The vulnerability was caused by the way Tor handles these cells, where the reason byte was read before checking the message length. This issue was compounded by Conflux's out-of-order delivery, which could copy the zero-length message into an exact-size heap allocation, leading to the out-of-bounds read. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/800/6e575d0a9127b91e83833cf4a9e6be6e8b30cbc3_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3709703' style='color: #4aa3ff;' target='new'> Tor onion service INTRODUCE2 invalid-MAC cells permanently grow service replay cache</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/geeknik?type=user' style='color: #4aa3ff;' target='new'> <strong> Brian Carpenter</strong></a> was disclosed at September 10, 2026, 12:10 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Tor's onion service INTRODUCE2 handling. A remote client could send well-formed INTRODUCE1 cells with an invalid MAC, but a unique byte pattern. The introduction point would forward these cells as INTRODUCE2 to the onion service. The onion service would insert the attacker-controlled encrypted section into the introduction-point replay cache before verifying the INTRODUCE2 MAC. The replay cache was created with no expiration, allowing the attacker to grow it with unauthenticated data until memory pressure or out-of-memory. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/800/6e575d0a9127b91e83833cf4a9e6be6e8b30cbc3_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3709605' style='color: #4aa3ff;' target='new'>Conflux-queued zero-length RELAY_END triggers heap out-of-bounds read</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/geeknik?type=user' style='color: #4aa3ff;' target='new'> <strong> Brian Carpenter</strong></a> was disclosed at September 10, 2026, 12:10 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Out-of-bounds Read</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Tor that could trigger a heap out-of-bounds read when a zero-length RELAY_END cell was processed on a non-open AP stream. The vulnerability was caused by the way Tor handles these cells, where the reason byte was read before checking the message length. This issue was compounded by Conflux's out-of-order delivery, which could copy the zero-length message into an exact-size heap allocation, leading to the out-of-bounds read. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/001/800/6e575d0a9127b91e83833cf4a9e6be6e8b30cbc3_original.jpg/1d3351b56b27c9bb56ce22821a57514a7210186a77aefb760cd2113272723c1f' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3709703' style='color: #4aa3ff;' target='new'> Tor onion service INTRODUCE2 invalid-MAC cells permanently grow service replay cache</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/geeknik?type=user' style='color: #4aa3ff;' target='new'> <strong> Brian Carpenter</strong></a> was disclosed at September 10, 2026, 12:10 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Tor's onion service INTRODUCE2 handling. A remote client could send well-formed INTRODUCE1 cells with an invalid MAC, but a unique byte pattern. The introduction point would forward these cells as INTRODUCE2 to the onion service. The onion service would insert the attacker-controlled encrypted section into the introduction-point replay cache before verifying the INTRODUCE2 MAC. The replay cache was created with no expiration, allowing the attacker to grow it with unauthenticated data until memory pressure or out-of-memory. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-08]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-08</link>
			<pubDate>Wed, 09 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-08</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3788482' style='color: #4aa3ff;' target='new'>Stack Buffer Overflow in mariadb-dump quote_name() Allows Malicious Server to Execute Arbitrary Code on Client</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/byteoverride?type=user' style='color: #4aa3ff;' target='new'> <strong> Byte Override</strong></a> was disclosed at September 8, 2026, 1:30 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Stack Overflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A stack buffer overflow was discovered in the quote_name() function of the mariadb-dump client application. The overflow occurred due to a lack of length validation on table names returned by a malicious MySQL server. This allowed a server to provide an excessively long table name that would overflow the fixed-size buffer, leading to the overwriting of the return address and other control-flow data on the stack. The vulnerability was confirmed to provide full control of the instruction pointer and several general-purpose registers, enabling remote code execution against any mariadb-dump client that connected to the malicious server. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3897914' style='color: #4aa3ff;' target='new'>Out-of-bounds read in MariaDB .frm parsing enables RCE via vtable hijacking</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/pinebudweiser?type=user' style='color: #4aa3ff;' target='new'> <strong> pinebudweiser</strong></a> was disclosed at September 8, 2026, 8:19 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Out-of-bounds Read</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in MariaDB where the `key_part->fieldnr` value parsed from a crafted `.frm` file was not validated before being used as an index into the `share->field[]` array. This resulted in an out-of-bounds read, allowing an attacker to hijack the C++ virtual method call and achieve arbitrary code execution within the context of the MariaDB server process. The vulnerability was successfully reproduced on MariaDB versions 10.4.18, 11.8.8, 12.3.2, and 13.1.0 Preview. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #dc3545; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Critical</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3788482' style='color: #4aa3ff;' target='new'>Stack Buffer Overflow in mariadb-dump quote_name() Allows Malicious Server to Execute Arbitrary Code on Client</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/byteoverride?type=user' style='color: #4aa3ff;' target='new'> <strong> Byte Override</strong></a> was disclosed at September 8, 2026, 1:30 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Stack Overflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A stack buffer overflow was discovered in the quote_name() function of the mariadb-dump client application. The overflow occurred due to a lack of length validation on table names returned by a malicious MySQL server. This allowed a server to provide an excessively long table name that would overflow the fixed-size buffer, leading to the overwriting of the return address and other control-flow data on the stack. The vulnerability was confirmed to provide full control of the instruction pointer and several general-purpose registers, enabling remote code execution against any mariadb-dump client that connected to the malicious server. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3897914' style='color: #4aa3ff;' target='new'>Out-of-bounds read in MariaDB .frm parsing enables RCE via vtable hijacking</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/pinebudweiser?type=user' style='color: #4aa3ff;' target='new'> <strong> pinebudweiser</strong></a> was disclosed at September 8, 2026, 8:19 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Out-of-bounds Read</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in MariaDB where the `key_part->fieldnr` value parsed from a crafted `.frm` file was not validated before being used as an index into the `share->field[]` array. This resulted in an out-of-bounds read, allowing an attacker to hijack the C++ virtual method call and achieve arbitrary code execution within the context of the MariaDB server process. The vulnerability was successfully reproduced on MariaDB versions 10.4.18, 11.8.8, 12.3.2, and 13.1.0 Preview. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-07]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-07</link>
			<pubDate>Tue, 08 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-07</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3876430' style='color: #4aa3ff;' target='new'>MariaDB GRANT PROXY permits unauthorized authentication changes and administrator account takeover</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/kevin_mizu?type=user' style='color: #4aa3ff;' target='new'> <strong> kevin_Mizu</strong></a> was disclosed at September 7, 2026, 8:07 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in MariaDB that allowed an authenticated user with only USAGE privileges to change the password of an existing administrator account. This was achieved through the grantee clause of the GRANT PROXY statement, which permitted bypassing the authorization checks and directly modifying the target account's authentication information. The vulnerability was tested on MariaDB versions 12.3.2 and 13.1.0. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3909248' style='color: #4aa3ff;' target='new'>MariaDB: heap buffer overflow in ha_tina::chain_append() lets a low-privileged user crash the server via CSV row deletion</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/v3rtical?type=user' style='color: #4aa3ff;' target='new'> <strong> Vertical</strong></a> was disclosed at September 7, 2026, 7:59 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Heap Overflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A heap buffer overflow vulnerability was discovered in the ha_tina::chain_append() function of the MariaDB database server. The vulnerability was caused by an incorrect memory allocation during the growth of a data structure. This could allow a low-privileged user to crash the server by executing a specific SQL command involving CSV data deletion. The vulnerability was confirmed to affect both the stock Ubuntu package and a source build of MariaDB. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3889667' style='color: #4aa3ff;' target='new'>ACL cache collision lets a role inherit privileges from a same-named socket user</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/dogeshark?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at September 7, 2026, 7:55 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in MariaDB's database privilege cache where a role and a UNIX-socket user with the same name were not distinguished. When the socket user warmed the cache with their privileges, a different account that activated the same-named role then received the cached user privileges, even though those privileges were never granted to the role. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3876430' style='color: #4aa3ff;' target='new'>MariaDB GRANT PROXY permits unauthorized authentication changes and administrator account takeover</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/kevin_mizu?type=user' style='color: #4aa3ff;' target='new'> <strong> kevin_Mizu</strong></a> was disclosed at September 7, 2026, 8:07 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Access Control - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in MariaDB that allowed an authenticated user with only USAGE privileges to change the password of an existing administrator account. This was achieved through the grantee clause of the GRANT PROXY statement, which permitted bypassing the authorization checks and directly modifying the target account's authentication information. The vulnerability was tested on MariaDB versions 12.3.2 and 13.1.0. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3909248' style='color: #4aa3ff;' target='new'>MariaDB: heap buffer overflow in ha_tina::chain_append() lets a low-privileged user crash the server via CSV row deletion</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/v3rtical?type=user' style='color: #4aa3ff;' target='new'> <strong> Vertical</strong></a> was disclosed at September 7, 2026, 7:59 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Heap Overflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A heap buffer overflow vulnerability was discovered in the ha_tina::chain_append() function of the MariaDB database server. The vulnerability was caused by an incorrect memory allocation during the growth of a data structure. This could allow a low-privileged user to crash the server by executing a specific SQL command involving CSV data deletion. The vulnerability was confirmed to affect both the stock Ubuntu package and a source build of MariaDB. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3889667' style='color: #4aa3ff;' target='new'>ACL cache collision lets a role inherit privileges from a same-named socket user</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/dogeshark?type=user' style='color: #4aa3ff;' target='new'> <strong> </strong></a> was disclosed at September 7, 2026, 7:55 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in MariaDB's database privilege cache where a role and a UNIX-socket user with the same name were not distinguished. When the socket user warmed the cache with their privileges, a different account that activated the same-named role then received the cached user privileges, even though those privileges were never granted to the role. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-06]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-06</link>
			<pubDate>Mon, 07 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-06</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/005/044/ba20ca159dad308d753710d2b8ae8dd665a60b80_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3828431' style='color: #4aa3ff;' target='new'>PII Exposure of Credit Applications and Social Security Numbers equifax-6070.my.salesforce-sites.com (Salesforce guest user)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/dr32?type=user' style='color: #4aa3ff;' target='new'> <strong> David Crees</strong></a> was disclosed at September 6, 2026, 10:03 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A Salesforce community portal belonging to Equifax was found to be leaking tens of thousands of credit reports and other sensitive financial information. The portal's Salesforce guest user profile and sharing settings granted unauthenticated access to multiple objects, including Contact, Online_Credit_Application__c, and related financial data. This exposure allowed an anonymous user to read a large number of records containing sensitive personally identifiable information. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/005/044/ba20ca159dad308d753710d2b8ae8dd665a60b80_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3828431' style='color: #4aa3ff;' target='new'>PII Exposure of Credit Applications and Social Security Numbers equifax-6070.my.salesforce-sites.com (Salesforce guest user)</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/dr32?type=user' style='color: #4aa3ff;' target='new'> <strong> David Crees</strong></a> was disclosed at September 6, 2026, 10:03 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A Salesforce community portal belonging to Equifax was found to be leaking tens of thousands of credit reports and other sensitive financial information. The portal's Salesforce guest user profile and sharing settings granted unauthenticated access to multiple objects, including Contact, Online_Credit_Application__c, and related financial data. This exposure allowed an anonymous user to read a large number of records containing sensitive personally identifiable information. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-05]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-05</link>
			<pubDate>Sun, 06 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-05</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3513471' style='color: #4aa3ff;' target='new'>Unauthenticated testing endpoint of notify_push expose internal IP</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/chinnuy935336?type=user' style='color: #4aa3ff;' target='new'> <strong> chinnuy</strong></a> was disclosed at September 5, 2026, 2:45 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Information Disclosure</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The testing endpoint of the notify_push component exposed internal IP addresses to unauthenticated users. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3507273' style='color: #4aa3ff;' target='new'>Email Enumeration via Password-Protected Share Identity Verification</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/cybershinu90?type=user' style='color: #4aa3ff;' target='new'> <strong> cybershinu</strong></a> was disclosed at September 5, 2026, 2:38 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Information Disclosure</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The vulnerability allowed email enumeration through password-protected share identity verification. Requesting a password for an email share resulted in different response messages depending on whether the email address was the intended recipient, enabling confirmation of the share recipient. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3521639' style='color: #4aa3ff;' target='new'>Improper Input Validation and Integer Overflow in timeamount parameter of files_retention app</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/nishantbaswal1996?type=user' style='color: #4aa3ff;' target='new'> <strong> nishant baswal</strong></a> was disclosed at September 5, 2026, 2:29 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Integer Overflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The timeamount parameter of the files_retention app lacked proper input validation, allowing an administrator to store an unintended long time amount as the retention period. This vulnerability could have potentially led to files never getting deleted. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3521646' style='color: #4aa3ff;' target='new'>Missing Duplicate Check allowing Multiple Retention Rules per System Tag</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/charankumar39?type=user' style='color: #4aa3ff;' target='new'> <strong> charankumar</strong></a> was disclosed at September 5, 2026, 2:23 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A bug allowed admins to create multiple retention rules for the same tag, causing potential confusion for other admins. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3534050' style='color: #4aa3ff;' target='new'>Activity app does not verify federated file activity received from remote servers </a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/cyebrsunita?type=user' style='color: #4aa3ff;' target='new'> <strong> cyebrsunita</strong></a> was disclosed at September 5, 2026, 2:18 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The activity app stored activity content received from remote servers without verifying the content first. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3513471' style='color: #4aa3ff;' target='new'>Unauthenticated testing endpoint of notify_push expose internal IP</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/chinnuy935336?type=user' style='color: #4aa3ff;' target='new'> <strong> chinnuy</strong></a> was disclosed at September 5, 2026, 2:45 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Information Disclosure</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The testing endpoint of the notify_push component exposed internal IP addresses to unauthenticated users. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3507273' style='color: #4aa3ff;' target='new'>Email Enumeration via Password-Protected Share Identity Verification</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/cybershinu90?type=user' style='color: #4aa3ff;' target='new'> <strong> cybershinu</strong></a> was disclosed at September 5, 2026, 2:38 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Information Disclosure</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The vulnerability allowed email enumeration through password-protected share identity verification. Requesting a password for an email share resulted in different response messages depending on whether the email address was the intended recipient, enabling confirmation of the share recipient. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3521639' style='color: #4aa3ff;' target='new'>Improper Input Validation and Integer Overflow in timeamount parameter of files_retention app</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/nishantbaswal1996?type=user' style='color: #4aa3ff;' target='new'> <strong> nishant baswal</strong></a> was disclosed at September 5, 2026, 2:29 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Integer Overflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The timeamount parameter of the files_retention app lacked proper input validation, allowing an administrator to store an unintended long time amount as the retention period. This vulnerability could have potentially led to files never getting deleted. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3521646' style='color: #4aa3ff;' target='new'>Missing Duplicate Check allowing Multiple Retention Rules per System Tag</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/charankumar39?type=user' style='color: #4aa3ff;' target='new'> <strong> charankumar</strong></a> was disclosed at September 5, 2026, 2:23 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Business Logic Errors</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A bug allowed admins to create multiple retention rules for the same tag, causing potential confusion for other admins. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3534050' style='color: #4aa3ff;' target='new'>Activity app does not verify federated file activity received from remote servers </a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/cyebrsunita?type=user' style='color: #4aa3ff;' target='new'> <strong> cyebrsunita</strong></a> was disclosed at September 5, 2026, 2:18 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Improper Authentication - Generic</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> The activity app stored activity content received from remote servers without verifying the content first. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-04]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-04</link>
			<pubDate>Sat, 05 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-04</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3617729' style='color: #4aa3ff;' target='new'>Mail contact autocomplete bypasses administrator-configured user enumeration restrictions and expose member information outside the intended scope</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/njh215?type=user' style='color: #4aa3ff;' target='new'> <strong> Jaeho Nam</strong></a> was disclosed at September 4, 2026, 8:38 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Privacy Violation</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Mail contact autocomplete feature of Nextcloud that allowed an authenticated user to bypass administrator-configured user enumeration restrictions and expose member information outside the intended scope. The vulnerability was present in the `ContactIntegrationController::autoComplete()` handler, which did not apply the stricter user enumeration controls used elsewhere in the product. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/468/71eb3827ae9f2a388f27bd4b7eefd20bc3ac813c_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3825141' style='color: #4aa3ff;' target='new'>API token sent to URL dictated by an untrusted project .weblate file</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/type5afe?type=user' style='color: #4aa3ff;' target='new'> <strong> type5afe</strong></a> was disclosed at September 4, 2026, 8:10 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Information Disclosure</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the wlc Python library used to interact with the Weblate translation management system. The vulnerability allowed an untrusted .weblate file to specify the Weblate API URL, which could then receive the API token set in the environment. The API token was resolved independently and was not bound to a trusted URL source, allowing the secret to be sent to an attacker-chosen server. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/468/71eb3827ae9f2a388f27bd4b7eefd20bc3ac813c_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3898281' style='color: #4aa3ff;' target='new'>Unauthenticated ?q= search query causes exponential pyparsing backtracking under a process-global lock in Weblate</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/type5afe?type=user' style='color: #4aa3ff;' target='new'> <strong> type5afe</strong></a> was disclosed at September 4, 2026, 8:10 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Weblate, an open-source translation management system. The vulnerability was caused by the search query grammar implementation in Weblate, which was built using the `pyparsing` library. The grammar was ambiguous at every position and did not enable memoization, leading to exponential backtracking during parsing of search queries with nested parentheses. This resulted in a significant performance impact, with a 33-byte query string consuming 52 seconds of CPU time. The parsing was performed while holding a process-global lock, causing all other search, browse, translate, and zen page requests to stall in the same worker process. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/hsgut1vi1cv8housqai9cm9383yx/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3617729' style='color: #4aa3ff;' target='new'>Mail contact autocomplete bypasses administrator-configured user enumeration restrictions and expose member information outside the intended scope</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/njh215?type=user' style='color: #4aa3ff;' target='new'> <strong> Jaeho Nam</strong></a> was disclosed at September 4, 2026, 8:38 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Privacy Violation</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the Mail contact autocomplete feature of Nextcloud that allowed an authenticated user to bypass administrator-configured user enumeration restrictions and expose member information outside the intended scope. The vulnerability was present in the `ContactIntegrationController::autoComplete()` handler, which did not apply the stricter user enumeration controls used elsewhere in the product. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/468/71eb3827ae9f2a388f27bd4b7eefd20bc3ac813c_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3825141' style='color: #4aa3ff;' target='new'>API token sent to URL dictated by an untrusted project .weblate file</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/type5afe?type=user' style='color: #4aa3ff;' target='new'> <strong> type5afe</strong></a> was disclosed at September 4, 2026, 8:10 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Information Disclosure</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the wlc Python library used to interact with the Weblate translation management system. The vulnerability allowed an untrusted .weblate file to specify the Weblate API URL, which could then receive the API token set in the environment. The API token was resolved independently and was not bound to a trusted URL source, allowing the secret to be sent to an attacker-chosen server. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/019/468/71eb3827ae9f2a388f27bd4b7eefd20bc3ac813c_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #fd7e14; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>High</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3898281' style='color: #4aa3ff;' target='new'>Unauthenticated ?q= search query causes exponential pyparsing backtracking under a process-global lock in Weblate</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/type5afe?type=user' style='color: #4aa3ff;' target='new'> <strong> type5afe</strong></a> was disclosed at September 4, 2026, 8:10 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Uncontrolled Resource Consumption</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in Weblate, an open-source translation management system. The vulnerability was caused by the search query grammar implementation in Weblate, which was built using the `pyparsing` library. The grammar was ambiguous at every position and did not enable memoization, leading to exponential backtracking during parsing of search queries with nested parentheses. This resulted in a significant performance impact, with a 33-byte query string consuming 52 seconds of CPU time. The parsing was performed while holding a process-global lock, causing all other search, browse, translate, and zen page requests to stall in the same worker process. </p>
              </div><br>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[HackerOne Disclosed Reports - 2026-09-03]]></title>
			<link>https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-03</link>
			<pubDate>Fri, 04 Sep 2026 07:00:03 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://darkcoders.wiki/member.php?action=profile&uid=2">hashXploiter</a>]]></dc:creator>
			<guid isPermaLink="false">https://darkcoders.wiki/Thread-HackerOne-Disclosed-Reports-2026-09-03</guid>
			<description><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3769676' style='color: #4aa3ff;' target='new'>Stack Overflow DoS in ST_GeomFromGeoJSON Allows Any Authenticated User to Crash the Entire Server</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/byteoverride?type=user' style='color: #4aa3ff;' target='new'> <strong> Byte Override</strong></a> was disclosed at September 3, 2026, 10:13 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Stack Overflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the MariaDB database server's ST_GeomFromGeoJSON function. Any authenticated user with basic SELECT privileges could crash the entire server by passing a deeply nested GeoJSON GeometryCollection. The crash was caused by unbounded recursion in the GeoJSON parser, which consumed the server's stack until it overflowed, leading to a SIGSEGV crash that killed all active connections and required a full server restart. The vulnerability existed since the introduction of ST_GeomFromGeoJSON in MariaDB 10.2.4 and affected all versions through the current development trunk. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/035/663/2faf4c279d437d64bfda6d23d62ce1833813a4d9_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3923520' style='color: #4aa3ff;' target='new'>CVE-2026-19931: Negotiate ambient user conn reuse</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/dukek?type=user' style='color: #4aa3ff;' target='new'> <strong> Martin Dukek</strong></a> was disclosed at September 3, 2026, 6:09 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Authentication Bypass by Primary Weakness</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/035/663/2faf4c279d437d64bfda6d23d62ce1833813a4d9_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3969368' style='color: #4aa3ff;' target='new'>CVE-2026-80231: native CA store conn reuse</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/giant_anteater?type=user' style='color: #4aa3ff;' target='new'> <strong> Anteater</strong></a> was disclosed at September 3, 2026, 6:08 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/035/663/2faf4c279d437d64bfda6d23d62ce1833813a4d9_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3822248' style='color: #4aa3ff;' target='new'>CVE-2026-13608: OpenLDAP SASL authentication bypass</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/hahahkim?type=user' style='color: #4aa3ff;' target='new'> <strong> Eunsoo Kim</strong></a> was disclosed at September 3, 2026, 12:35 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Authentication Bypass by Primary Weakness</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the OpenLDAP SASL authentication mechanism in libcurl. The vulnerability could allow a malicious LDAP server to bypass SASL authentication, potentially allowing the injection of arbitrary LDAP results. The vulnerable code has been present since the OpenLDAP SASL support was introduced and was unchanged in the current release. </p>
              </div><br>]]></description>
			<content:encoded><![CDATA[<div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/008/724/6a67872926e894490b4fdc36cd6a3f59e300616b_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3769676' style='color: #4aa3ff;' target='new'>Stack Overflow DoS in ST_GeomFromGeoJSON Allows Any Authenticated User to Crash the Entire Server</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/byteoverride?type=user' style='color: #4aa3ff;' target='new'> <strong> Byte Override</strong></a> was disclosed at September 3, 2026, 10:13 pm &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Stack Overflow</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the MariaDB database server's ST_GeomFromGeoJSON function. Any authenticated user with basic SELECT privileges could crash the entire server by passing a deeply nested GeoJSON GeometryCollection. The crash was caused by unbounded recursion in the GeoJSON parser, which consumed the server's stack until it overflowed, leading to a SIGSEGV crash that killed all active connections and required a full server restart. The vulnerability existed since the introduction of ST_GeomFromGeoJSON in MariaDB 10.2.4 and affected all versions through the current development trunk. </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/035/663/2faf4c279d437d64bfda6d23d62ce1833813a4d9_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #ffc107; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Medium</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3923520' style='color: #4aa3ff;' target='new'>CVE-2026-19931: Negotiate ambient user conn reuse</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/dukek?type=user' style='color: #4aa3ff;' target='new'> <strong> Martin Dukek</strong></a> was disclosed at September 3, 2026, 6:09 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Authentication Bypass by Primary Weakness</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/035/663/2faf4c279d437d64bfda6d23d62ce1833813a4d9_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3969368' style='color: #4aa3ff;' target='new'>CVE-2026-80231: native CA store conn reuse</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/giant_anteater?type=user' style='color: #4aa3ff;' target='new'> <strong> Anteater</strong></a> was disclosed at September 3, 2026, 6:08 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'></span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'>  </p>
              </div><br><div style='background: #1e1e1e;padding: 15px;border-radius: 8px;box-shadow: 0px 2px 5px rgba(0, 0, 0, 0.2);margin: auto;'>
                <div style='display: flex; justify-content: space-between; align-items: center;'>
                    <div> <img src='https://profile-photos.hackerone-user-content.com/variants/000/035/663/2faf4c279d437d64bfda6d23d62ce1833813a4d9_original.png/89f037b490baf3dcca1b84283f4c85141b64c213252a9c79b56c62bf903ab542' alt='Logo' style='width: 40px; height: 40px; border-radius: 50%;'> </div>
                    <div style='display: flex; gap: 5px;'>
                        <span style='background: #17a2b8; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>Low</span><br />
                        <span style='background: #28a745; color: white; padding: 5px 10px; border-radius: 12px; font-size: 12px;'>resolved</span><br />
                    </div>
                </div>
                <h2 style='color: #4aa3ff;font-size: 18px;margin-top: 10px;'> <a href='https://hackerone.com/reports/3822248' style='color: #4aa3ff;' target='new'>CVE-2026-13608: OpenLDAP SASL authentication bypass</a></h2><br />
                <p style='font-size: 14px;color: #bbb;margin-top: 5px;'> Bug reported by <a href='https://hackerone.com/hahahkim?type=user' style='color: #4aa3ff;' target='new'> <strong> Eunsoo Kim</strong></a> was disclosed at September 3, 2026, 12:35 am &nbsp; | &nbsp; <span style='color: #ff6b6b;'>Authentication Bypass by Primary Weakness</span> </p>
                <p style='font-size: 14px; color: #aaa; margin-top: 10px;'> A vulnerability was discovered in the OpenLDAP SASL authentication mechanism in libcurl. The vulnerability could allow a malicious LDAP server to bypass SASL authentication, potentially allowing the injection of arbitrary LDAP results. The vulnerable code has been present since the OpenLDAP SASL support was introduced and was unchanged in the current release. </p>
              </div><br>]]></content:encoded>
		</item>
	</channel>
</rss>