Bug Bounty Channel
π Analytical overview of Telegram channel Bug Bounty Channel
Channel Bug Bounty Channel (@bug_bounty_channel) in the English language segment is an active participant. Currently, the community unites 15 747 subscribers, ranking 7 144 in the Technologies & Applications category and 30 273 in the India region.
π Audience metrics and dynamics
Since its creation on Π½Π΅Π²ΡΠ΄ΠΎΠΌΠΎ, the project has demonstrated rapid growth, gathering an audience of 15 747 subscribers.
According to the latest data from 29 December, 2025, the channel demonstrates stable activity. Although there has been a change in the number of participants by -49 over the last 30 days and by 0 over the last 24 hours, overall reach remains high.
- Verification status: Not verified
- Engagement rate (ER): The average audience engagement rate is 0%. Within the first 24 hours after publication, content typically collects N/A% reactions from the total number of subscribers.
- Post reach: On average, each post receives 0 views. Within the first day, a publication typically gains 0 views.
- Reactions and interaction: The audience actively supports content: the average number of reactions per post is 0.
- Thematic interests: Content is focused on key topics such as cve, cwe, reporter, severity, none.
π Description and content policy
The author describes the resource as a platform for expressing subjective opinions:
βAll bug bounties here.β
Thanks to the high frequency of updates (latest data received on 30 December, 2025), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.
Data loading in progress...
| Date | Subscriber Growth | Mentions | Channels | |
| 28 December | 0 | |||
| 27 December | 0 | |||
| 26 December | 0 | |||
| 25 December | +2 | |||
| 24 December | +1 | |||
| 23 December | +4 | |||
| 22 December | 0 | |||
| 21 December | 0 | |||
| 20 December | +2 | |||
| 19 December | 0 | |||
| 18 December | +1 | |||
| 17 December | 0 | |||
| 16 December | +1 | |||
| 15 December | +3 | |||
| 14 December | 0 | |||
| 13 December | 0 | |||
| 12 December | +4 | |||
| 11 December | +10 | |||
| 10 December | 0 | |||
| 09 December | +1 | |||
| 08 December | 0 | |||
| 07 December | +2 | |||
| 06 December | 0 | |||
| 05 December | +1 | |||
| 04 December | 0 | |||
| 03 December | 0 | |||
| 02 December | 0 | |||
| 01 December | +2 |
| 2 | π¦ curl Report
β οΈ Title: HTTP Proxy Bypass via `CURLOPT_CUSTOMREQUEST` Verb Tunneling
π Reporter: alphox (Alphox)
π Details:
β π Status: not-applicable
β β‘ Severity: High
β π― CWE: Improper Access Control - Generic
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-07-01 14:20:30 UTC
β π Created: 2025-07-01 12:47:44 UTC | 1 591 |
| 3 | π¦ curl Report
β‘ Title: Speculative Execution Side-Channel in `curl`
π Reporter: evilginx1 (Lots-o'-Huggin' Bear)
π Details:
β π Status: not-applicable
β β‘ Severity: Medium
β π― CWE: Authentication Bypass by Primary Weakness
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-07-01 14:09:27 UTC
β π Created: 2025-05-03 05:56:15 UTC | 1 258 |
| 4 | π¦ curl Report
β‘ Title: arbitrary file read via `file://` path traversal with `--path-as-is`
π Reporter: demsese (yeabsira)
π Details:
β π Status: not-applicable
β β‘ Severity: Medium
β π― CWE: Path Traversal
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-07-01 14:08:38 UTC
β π Created: 2025-06-27 09:42:53 UTC | 1 141 |
| 5 | π¦ curl Report
β Title: curl_easy_header runs at O(N) or worse and can be abused to use minute(s) of CPU time
π Reporter: wolfsage (alh)
π Details:
β π Status: informative
β β‘ Severity: Not Specified
β π― CWE: Uncontrolled Resource Consumption
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-07-01 14:07:31 UTC
β π Created: 2025-05-07 19:25:48 UTC | 974 |
| 6 | π¦ curl Report
π Title: curl -OJ allows creating custom .curlrc file which allows exfiltrating private data, among other things
π Reporter: wolfsage (alh)
π Details:
β π Status: not-applicable
β β‘ Severity: None
β π― CWE: Not Specified
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-07-01 14:07:45 UTC
β π Created: 2025-05-08 15:53:37 UTC | 825 |
| 7 | π¦ Yelp Report
β‘ Title: RXSS AT https://proze.yelp.com/tmsubscribe.net/vidsn.aspx
π Reporter: 0xold (0xold)
π Details:
β π Status: resolved
β β‘ Severity: Medium
β π― CWE: Cross-site Scripting (XSS) - Reflected
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-30 15:06:44 UTC
β π Created: 2025-01-19 03:12:51 UTC | 943 |
| 8 | π¦ Tools for Humanity Report
π Title: Unlock underage blocked app without support interaction using airplane mode
π Reporter: polem4rch (Polem4rch)
π Details:
β π Status: resolved
β β‘ Severity: Low
β π― CWE: Business Logic Errors
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-30 11:20:50 UTC
β π Created: 2025-05-09 04:29:40 UTC | 975 |
| 9 | π¦ curl Report
β οΈ Title: Heap Buffer Overflow in libcurl curl_slist_append via Unterminated String
π Reporter: geeknik (Brian Carpenter)
π Details:
β π Status: not-applicable
β β‘ Severity: High
β π― CWE: Heap Overflow
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-30 07:23:15 UTC
β π Created: 2025-06-29 17:33:41 UTC | 1 028 |
| 10 | π¦ curl Report
π Title: Memory leak from doh_write_cb
π Reporter: catenacyber (Philippe Antoine)
π Details:
β π Status: informative
β β‘ Severity: None
β π― CWE: Allocation of Resources Without Limits or Throttling
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-29 19:12:35 UTC
β π Created: 2025-04-11 20:06:53 UTC | 1 011 |
| 11 | π¦ curl Report
β οΈ Title: HTTP/2 CONTINUATION Flood Vulnerability
π Reporter: evilginx1 (Lots-o'-Huggin' Bear)
π Details:
β π Status: not-applicable
β β‘ Severity: High
β π― CWE: Allocation of Resources Without Limits or Throttling
β π’ CVE: CVE-2023-44487
β° Timeline:
β π Disclosed: 2025-06-28 21:13:12 UTC
β π Created: 2025-05-04 04:10:47 UTC | 1 043 |
| 12 | π¦ curl Report
π₯ Title: Buffer Overflow in curl MQTT Test Server (tests/server/mqttd.c) via Malicious CONNECT Packet
π Reporter: deep-hackerone (Deepak Dubey)
π Details:
β π Status: not-applicable
β β‘ Severity: Critical
β π― CWE: Memory Corruption - Generic
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-28 21:11:25 UTC
β π Created: 2025-04-19 20:20:07 UTC | 925 |
| 13 | π¦ curl Report
β οΈ Title: Path Traversal Vulnerability in curl via Unsanitized IPFS_PATH Environment Variable
π Reporter: ziad616 (Ziad Salah)
π Details:
β π Status: not-applicable
β β‘ Severity: High
β π― CWE: Path Traversal
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-28 21:11:42 UTC
β π Created: 2025-04-18 17:41:19 UTC | 825 |
| 14 | π¦ curl Report
β Title: Free of uninitialized pointer in doh_decode_rdata_name()
π Reporter: tdp3kel9g (Ronald Crane (Zippenhop LLC))
π Details:
β π Status: informative
β β‘ Severity: Not Specified
β π― CWE: Use After Free
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-28 21:10:50 UTC
β π Created: 2025-03-13 21:59:27 UTC | 781 |
| 15 | π¦ curl Report
π₯ Title: Improper Restriction of Authentication Attempts in cURL
π Reporter: irfanmughal1122 (irfan)
π Details:
β π Status: not-applicable
β β‘ Severity: Critical
β π― CWE: Improper Restriction of Authentication Attempts
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-28 21:09:52 UTC
β π Created: 2025-03-10 21:00:59 UTC | 739 |
| 16 | π¦ curl Report
β‘ Title: Stack Buffer Overflow in curl's OpenSSL Provider Handling
π Reporter: oblivionsage (No name)
π Details:
β π Status: not-applicable
β β‘ Severity: Medium
β π― CWE: Stack Overflow
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-28 12:40:36 UTC
β π Created: 2025-05-20 00:07:26 UTC | 864 |
| 17 | π¦ curl Report
β οΈ Title: OS Command Injection in scripts/firefox-db2pem.sh via untrusted certificate nicknames
π Reporter: behindtheblackwall (Tacitus)
π Details:
β π Status: informative
β β‘ Severity: High
β π― CWE: OS Command Injection
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-28 12:19:19 UTC
β π Created: 2025-06-26 21:10:59 UTC | 875 |
| 18 | π¦ TikTok Report
π Title: Unauthorized Access to Private Video Description via Translation API for Private Accounts
π Reporter: z3phyrus (Zephyrus)
π Details:
β π Status: resolved
β β‘ Severity: Low
β π― CWE: Insecure Direct Object Reference (IDOR)
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-27 20:24:33 UTC
β π Created: 2025-01-04 04:55:52 UTC | 1 016 |
| 19 | π¦ Basecamp Report
π₯ Title: Mutation Based Stored XSS on Trix Editor version latest (2.1.8)
π Reporter: sudi (Sudhanshu Rajbhar)
π Details:
β π Status: resolved
β β‘ Severity: Critical
β π― CWE: Not Specified
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-27 12:55:01 UTC
β π Created: 2024-11-04 14:09:01 UTC | 1 012 |
| 20 | π¦ curl Report
β‘ Title: Failure to strip Proxy-Authorization header on change in origin
π Reporter: grahamcampbell (Graham Campbell)
π Details:
β π Status: not-applicable
β β‘ Severity: Medium
β π― CWE: Information Disclosure
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-06-27 09:48:04 UTC
β π Created: 2025-06-06 01:26:57 UTC | 1 067 |
