HackerOne Bug Bounty: HTTP Proxy Vulnerability Discovered

HackerOne Bug Bounty: HTTP Proxy Vulnerability Discovered

First seen 9 Sep 2026, 18:45 UTC Redpacketsecurity 18.1

Article Content

Browse articles
ThreatCluster

A vulnerability was disclosed in the HTTP proxy CONNECT header that allows the filename to be chosen after a redirect. This issue was reported by a user named Anteater on HackerOne and was submitted on September 7, 2026. The specific report is titled 'HTTP proxy CONNECT header chooses the `-OJ` filename after a redirect'. The scope of impact and affected systems have not been detailed in the articles. As of now, there are no indications of active exploitation or proof-of-concept code publicly available. The vulnerability is currently in the disclosure phase, with no patches or fixes mentioned. Security professionals are advised to monitor for updates regarding this issue.

Key Points: • Vulnerability affects HTTP proxy CONNECT header functionality. • Reported by user Anteater on HackerOne on September 7, 2026. • No active exploitation or proof-of-concept code reported yet.

Ask AI about this cluster

Timeline

2026-09-07
Vulnerability reported on HackerOne
User Anteater submitted a report detailing the HTTP proxy CONNECT header vulnerability.
Redpacketsecurity
2026-09-08
First article published
Redpacketsecurity published an article summarizing the HackerOne report on the vulnerability.
Redpacketsecurity
2026-09-09
Second article published
A follow-up article was published on Redpacketsecurity with similar content regarding the vulnerability.
Redpacketsecurity