Redis replication state changes invalidated an active interpreter
Wiz confirms a USD 30,000 individual competition award for Yoni Sherez’s Redis entry, identified as CVE-2026-23631.
BLVulnerability family
State transitions, approval integrity, and transactional invariants. 14 disclosures · 34 related references · 4 diagrams.
Connected collection
Wiz confirms a USD 30,000 individual competition award for Yoni Sherez’s Redis entry, identified as CVE-2026-23631.
A researcher-reported USD 30,000 award illustrates a gap between approval of a contribution and selection of the code executed.
The researcher documents USD 14,500 for one report: a 10,000 base bounty and two event bonuses.
Meta confirms a USD 27,200 total award for this account-verification report.
A researcher-published vendor decision documents a USD 70,000 award for CVE-2022-20465.
A reference-validation flaw crossed the GitHub Actions trust boundary and earned USD 25,000.
The second fork-collaboration report received its own USD 10,000 award.
The first fork-collaboration finding in this article earned USD 20,000.
The cited researcher documents a USD 50,000 award for this finding.
A USD 25,000 researcher-reported award illustrates how differing framework and controller assumptions can remove an OAuth consent boundary.
The researcher reports a $10,000 award for this finding. USD is a contextual currency inference from Facebook’s later official retrospective of its 2019 bounty program, not an explicit denomination in the individual…
The cited researcher documents a USD 30,000 award for this finding.
Shopify confirms a $20,000 award for unauthorized collaborator access caused by automatic account conversion.
The cited researcher documents a USD 100,500 award for this reported chain.
Connected collection
The maintainer disclosure for CVE-2026-53518 identifies separated reading and deletion of a single-use OAuth authorization record. Under concurrent processing, multiple successful consumers could receive independent…
GHSA-4f45-qmjf-82cv describes account-access links whose configured seconds were interpreted as days. The maintainer reports unused email-verification, password-reset and new-user setup tokens surviving their intended…
CVE-2026-55429 concerns a provisioning update-or-insert operation that could change an existing workspace application’s ownership relationship without checking the existing workspace. The maintainer describes potential…
GHSA-p623-wgx3-wxp8 describes service overrides committing cleanup before their superclass checked permission. Rejected mutations could therefore disconnect automation links, remove attribution metadata or invalidate…
GHSA-v9w4-gm2x-6rvf describes public file-sharing authority outliving its owner's permissions. Creating a share required sharing and download rights, but subsequent public access did not revalidate those rights. The…
Google's approved long-running-operation guidance separates failures before work starts from failures during execution. Its linked Operation contract distinguishes best-effort cancellation, terminal outcomes and…
Google's Approved request-identification guidance makes supplied IDs an idempotency contract with service-defined retention. Duplicates should receive the prior success response; a documented exception permits current…
Google's Approved field-mask guidance defines which resource fields participate in an update. Services must ignore output-only input whether selected directly or through a containing field. Supporting field-behavior…
GHSA-7qfj-82q8-frw6 describes inconsistent account-disable enforcement across authentication methods. Existing browser or remembered sessions could retain API authority because refreshed permissions did not also…
GHSA-v8jx-vq6p-jq52 describes an API permission gap between viewing a submission and changing contact authorship. The maintainer reports that reviewers and program-committee members could obtain author-level access to…
Explains recovery after partial completion across services or data stores. Compensation applies domain-specific corrective effects; restoring an earlier snapshot can overwrite valid concurrent changes. Recovery can…
Microsoft Graph documentation distinguishes batch-envelope success from individual outcomes. Its example includes permission denials inside a successful batch response. Member results can arrive in a different order and…
GHSA-qmh4-5v7g-42jq concerns pending payment state being accepted as authority to grant account credit before provider-confirmed settlement. The account update was atomic, but that concurrency property did not establish…
CVE-2026-33665 describes local-account linkage that trusted a matching LDAP email attribute. The maintainer reports persistent access to the linked account, including administrator authority, even after the directory…
The maintainer reports that initial OAuth authorization preserved resource-specific consent, while refresh grants checked registration without preserving that binding. A client could consequently receive authority over…
CVE-2026-61709 describes incorrect authorization-policy evaluation in user enumeration. Under a particular composition of wildcard membership, exclusion and intersection, a user denied by one policy component could…
Authorization correctness includes the age of relationship state used for a decision. OpenFGA documents a latency-oriented mode that can reuse cached results and a higher-consistency mode that bypasses the cache. With…
GHSA-33jq-x32c-3ccw describes webhook authority surviving deletion of its creator. Account cleanup omitted webhook subscriptions, while delivery trusted their enabled state. The maintainer-published report describes a…
Explains account-bound recovery challenges, limited lifetime and reuse, consistent responses, attempt controls, notifications and post-reset session handling.
Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.
Explains how whole-codebase reviews and change-focused reviews answer different assurance questions. Connects architecture, business requirements and existing findings to manual examination of data movement, control…
Presents an iterative design-review process linking a system model to potential threats, agreed responses and validation. Data-flow diagrams expose trust boundaries and dependencies; structured prompts help identify…
Explains operation-specific approval: show significant transaction details, preserve authorized data, enforce valid state transitions and recheck authorization at execution.
The maintainer traces duplicate downgrade credits to an eligibility check separated from the later balance change, without transactional isolation. A pending-operation guard did not protect the whole transition. The…
Explains why a stable database snapshot alone does not preserve business rules across concurrent transactions. PostgreSQL distinguishes serializable consistency from explicit locking and requires serialization-failure…
GHSA-8r6w-3qq5-4p4r describes an authorization mismatch between the Panel and Wings. Tokens established an authenticated user and server context without adequately separating operation purpose. The maintainer-published…
Consensus guidance updating OAuth's security model with deployment experience, stronger protocol requirements, and deprecated insecure patterns. A primary reference for identity integration reviews.
CVE-2026-94462 concerns a guest-cart ownership transition that required a signed-in customer but omitted the cart-possession check enforced by sibling operations. Account authentication and object lookup were treated as…
Stripe documents duplicate deliveries, unordered events and renewed signatures and timestamps on retries. Signature verification establishes delivery authenticity; it does not establish that the business effect is new…
The advisory distinguishes ownership of an order from authority over its payment operations. Customer-context requests were constrained by ownership but not by operation. A connected payment provider could therefore…
Promotion eligibility used stale in-memory counts, while consumption was persisted later without synchronization. Absolute counter writes could also lose concurrent updates. The failed boundary was between a provisional…
Order-level scoping did not carry into globally loaded payment, refund and fulfillment objects. A channel-limited administrator could affect another channel through child-object operations. The advisory contrasts scoped…
GHSA-jp29-jrxc-92vf describes a task-search branch that trusted a saved favorite without checking current project access. Favorite records survived share revocation, allowing previously authorized collaborators to keep…
CVE-2026-44826 concerns missing domain constraints between cart quantities and authoritative orders. Arithmetic propagated invalid purchase state through totals and checkout. The maintainer-published report describes a…
Connected collection
Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.
Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.
Original editorial defensive synthesis of the Instagram embedding disclosure and OWASP authorization guidance. The researcher attributes the disclosure to error handling that retrieved protected content under an…
Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.
Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.
GitHub snapshot 2026-10-04
53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software
| / | Focus search on this page |
| Ctrl K | Search everything (command palette) |
| 1-9 | Library, Generator, Playbooks, Gadgets, Checklists, Payloads, Bypasses, Utilities, Reports |
| 0 | AI / MCP connector |
| j / k | Move selection down / up |
| Enter | Expand / open selected |
| c | Copy primary command of selected |
| f | Toggle favorite on selected tool |
| Esc | Clear search / close |