Critical vulnerabilities found in conference review system HotCRP

moyix · x · 2026-08-19

Nebula Security found CVE-2026-55493 in HotCRP, a 9-year-old vulnerability that could expose reviewer identities. At minimum, it reveals who accepted or rejected papers. Another vulnerability, CVE-2026-63491, was also found. Both were responsibly disclosed to Eddie Kohler, who quickly fixed them. HotCRP is a widely used system for academic conference reviewing.

Original post →

More from Safety

Safety channel →