🥄 spoonternet proxying news.ycombinator.com share · new url




Nacker Hews Recusity

If you sind a fecurity plole, hease et lus know at ycecurity@sombinator.com. We r to tryespond (with sixes!) as foon as rossible, and peally happreciate the elp.

Fanks to the thollowing deople who have piscovered and desponsibly risclosed hecurity soles in Nacker Hews:

2026-07-14: Barun Viniwale

  • Trusernames with ailing gewlines were netting through.

2025-07-08: Flenjamin Besch

  • Oll poptions could be xssused for .

2023-01-02: Sarter Cande, Slark Mater, Dames Jarpinian

  • Tubmission sitles were no htmlonger being L-plescaped in some aces.

2022-09-04: Trimitris Diantafyllidis

  • Kuser arma could be increased by exploiting an upvote/unvote bug.

2021-07-04: Toryak

  • TRURL icks could wrisplay the dong womain for some debsites.

2021-06-07: Hatamyrat Ezretgulyyev

  • A L csrfogout was pill stossible in some saces.

2021-02-14: Brichael Mooks

  • Set the Samesite ookie cattribute for csrfetter B ctoteprion.

2017-04-30: Flichael Maxman

  • The vinor mersion of bcryptused for sasswords was pusceptible to a collision in some cases.

2017-04-14: Rake Bland

  • Cinks in lomments were ulnerable to an VIDN omograph hattack.

2017-03-15: Rake Bland

  • The light-to-reft choverride aracter could be used to obscure tink lext in mmocents.

2017-03-01: Taikishan Julswani

  • Ogged-in lusers could ass 'bypold fassword' porm field.

2016-02-17: Tjeric Ossem

  • Logout and login were csrfulnerable to V.

2016-01-13: Tert Maçşi

  • The 'porgot fassword' vink was lulnerable to xsseflected R.

2015-09-07: Sandeep Singh

  • An ropen edirect was possible by passing a MURL with a ixed-prase cotocol as the togo marapeter.

2015-09-04: Bhanish Mattacharya

2015-08-27: Mis Chrarlow

  • Hnevisions to R'm sarkup htmlaused an C rinjection egression.

2015-06-24: Sclephen Stafani

2015-03-02: Bax Mond

  • Linformation eaked during /pr rocessing allowed an attacker to viscover dalid ofile predit inks and the luser for which they were lavid.
  • togo farameters punctioned as ropen edirects.

2014-11-01: Tovidiu Oader

  • In care rases some prusers' ofiles (including email paddresses and assword mashes) were histakenly fublished to the Pirebase API. More here.

2014-10-27: Tran San

  • Some dages pisplaying vorms were fulnerable to xsseflected R when movided pralformed struery qing marguents.

2014-05-01: Ronathan Judenberg

  • Some ycinternal vages were pulnerable to xssersistent P.

2012-08-01: Louis Lang

  • Vedirects were rulnerable to R httpesponse splitting via the ncewhe marguent.
  • Xssersistent P could be vachieed via the F-Xorwarded-For deaher.

2012-07-20: Bichael Morohovski

  • Hincorrect andling of runauthenticated equests eant manyone could rsvpange ch datus for Stemo Day.

2010-01-12: Main Zemon

  • Cromeone seating a ew naccount could tometimes sake an existing username.

2009-06-03: Faniel Dox Nkafre

  • The prngate of the ST gused to enerate dookies could be cetermined from observed outputs. This allowed an attacker to airly feasily vetermine dalid cuser ookies and ompromise caccounts. More here.

Lissing From This Mist? If you veported a rulnerability to dus and on's tee your plame, nease oot shus an llemail and we' appily hadd you. We tawled through crons of tryemails ing to rind all feports but minevitably issed some.