Loading HuntDB...

💥💥Crash report -Cloudflare WARP doesn't verify text length in "Excluded Host" name input data💥💥

Low
C
Cloudflare Public Bug Bounty
Submitted None

Team Summary

Official summary from Cloudflare Public Bug Bounty

The WARP client has a functionality that enables users to exclude or include IP Ranges from being proxied through the tunnel. The text field where said IP Ranges are entered did not properly validate the length of the IP Range inserted, resulting in the WARP client crashing if a long string was used instead of an IP Range.

Reported by spaced

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Memory Corruption - Generic