Bounties
Partners
Community
Info
heroiclabs / nakama
Project repository
Distributed server for social and realtime games and apps.
Submit a report
FIRST INTERACTION
WITHIN
6 DAYS
REVIEW
WITHIN
39 DAYS
FIX
WITHIN
86 DAYS
SQL Injection
Jul 4th 2023
h3athen
•
pending
Deleting user has no validation which can result to Admin delete's its own accou...
May 3rd 2023
rac-fckscty
•
pending
Broken Link Hijacking
Apr 28th 2023
oiiwroo
•
pending
No rate limiting on the reset password page will lead to a DOS attack and inbox...
Apr 24th 2023
oiiwroo
•
self closed
No Protection Against Bruteforce Attacks on Admin Login Page
Apr 22nd 2023
oiiwroo
•
pending
No rate limit On Forgot Password Lead To Dos and inbox flooding for any user
Apr 20th 2023
novemberdad
•
informative
High
open redirect
Mar 28th 2023
oiiwroo
•
pending
Exposure of Resource to Wrong Sphere
Apr 14th 2023
louis-xer
•
not applicable
Multiple user accounts creation with same email
Feb 17th 2023
earth2sky
•
pending
Deleted User Is Able To Access His Account And Can Create New Accounts
Feb 17th 2023
earth2sky
•
pending
Weak password policy implemented
Feb 17th 2023
earth2sky
•
pending
The session token is not invalidated when deleting the account
Feb 14th 2023
juylang
•
duplicate
High
Sha1 hashing algorithm in use for node
Jan 25th 2023
popcorn94
•
not applicable
grpc server Insecure connection
Jan 7th 2023
captain-k-101
•
pending
nakama does not properly termine existing user sessions when the user was delet...
Jan 25th 2023
lujiefsi
•
duplicate
High
Lack of email validation lead to account takeover
Jan 25th 2023
rezaduty
•
not applicable
Lack of ratelimit in authenticate
Jan 25th 2023
rezaduty
•
not applicable
API Key Disclosure via main.js
Jan 25th 2023
bash-shocker
•
not applicable
Session not exipiry after password change...
Nov 4th 2022
raja453
•
pending
Verify and password reset token revealing the user's email and user id on web:ht...
Jan 25th 2023
raja453
•
informative
Medium
No Rate limit protection on https://cloud.heroiclabs.com/login
Nov 2nd 2022
raja453
•
pending
Multiple user creation with the same email Id bypassed with uppercase
Jan 25th 2023
moutainpink
•
duplicate
Critical
DOS at login function
Oct 21st 2022
ch1nhpd
•
pending
no-rate limit leads to mail throttling ( mail flooding )
Oct 18th 2022
drxadz
•
pending
Multiple user accounts via same email and username
Feb 1st 2023
nerrorsec
•
High
•
$165
High
•
$165
UI Discrepancy in Password
Feb 1st 2023
nerrorsec
•
Medium
•
$45
Medium
•
$45
Login bruteforce
Feb 1st 2023
effectrenan
•
High
•
$165
High
•
$165
Insufficient Session Expiration
Feb 1st 2023
vautia
•
Medium
•
$45
Medium
•
$45
User Enumeration via Response Timing
Feb 1st 2023
vautia
•
Medium
•
$45
Medium
•
$45
horizontal privilege escalation
Aug 22nd 2022
drxadz
•
not applicable
miss-configuration of Authorization Bearer token lead to account tackover
Aug 18th 2022
drxadz
•
informative
Critical
Admin account takeover using response manipulation
Aug 18th 2022
sandeep-vatada
•
not applicable
no rate limit on the REST API leads to multiple UserID and Username creation
Jul 28th 2022
drxadz
•
informative
High
Clickjacking to delete user accounts
Jul 14th 2022
themarkib
•
duplicate
High
Business logic error: Not able to access newly created admin account with the us...
Jul 28th 2022
drxadz
•
High
•
$165
High
•
$165
No access control in ClockroachDB
Jul 6th 2022
shadowfl0w
•
informative
Medium
RSA Private Key Leak
Jul 6th 2022
thwinhtetwin
•
informative
Critical
Unsigned application
Aug 22nd 2022
ap062
•
informative
High
JWT token leakage in HTTP response leads to user information exposure
Jul 5th 2022
khanhchauminh
•
informative
High
Clickjacking leads to user account deletion
Jul 4th 2022
akshayravic09yc47
•
duplicate
Medium
Account takeover
Jul 4th 2022
akshayravic09yc47
•
duplicate
High
Multiple user creation with the same email Id via existing verification bypass
Jul 4th 2022
drxadz
•
Medium
•
$45
Medium
•
$45
Insufficient Brute Force Protection in Login Portal (Self hosted and cloud.heroi...
Jul 4th 2022
dievus
•
duplicate
Critical
Use of Hard-coded Cryptographic Key
Jul 4th 2022
cokebeer
•
informative
Critical
Session tokens are not invalidated on logout
Jul 4th 2022
nerrorsec
•
High
•
$165
High
•
$165
•
CVE-2022-2306
CVE-2022-2306
User Account Deletion and more via Clickjacking
Jul 6th 2022
nerrorsec
•
High
•
$165
High
•
$165
No Protection against Bruteforce attacks on Login page
Jul 5th 2022
nerrorsec
•
High
•
$165
High
•
$165
•
CVE-2022-2321
CVE-2022-2321
Improper authorization on view only user
May 20th 2022
tienpa99
•
duplicate
High
identify registered user
May 20th 2022
ranjit-git
•
Low
Low
unprivileged user can see user details like email,role etc
May 20th 2022
ranjit-git
•
Low
Low
Improper Privilege Management
May 20th 2022
thelabda
•
Medium
•
$65
Medium
•
$65
Observable Response Discrepancy
Feb 21st 2022
thelabda
•
Medium
Medium
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0