- Authentication bypass on gist.github.com through SSH Certificates, 10,000 USD
- The `io.kubernetes.client.util.generic.dynamic.Dynamics` contains a code execution vulnerability due to SnakeYAML, 1,000 USD
- ReDoS( Ruby, Time), 4,000 USD
- Blind SSRF to internal services in matrix preview_link API, 6,000 USD
- Desktop client does not verify received singed certificate in end to end encryption, 1,000 USD
- Information disclosure by sending a GIF, 500 USD