Episode

Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS

Podcast
Critical Thinking - Bug Bounty Podcast
Published
Feb 5, 2026
Duration seconds
2704
Processing state
not_requested
Canonical source
https://criticalthinkingpodcast.io
Audio
https://audio-delivery.cohostpodcasting.com/audio/8d5e4388-13f4-45c8-b82f-aff313a5ac76/episodes/0dfa5fbe-fddf-42ee-9511-c083ad993202/episode.mp3
JSON
/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-160-cloudflare-zero-days-mail-unsubscribing-for-xss
Markdown
/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-160-cloudflare-zero-days-mail-unsubscribing-for-xss.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-160-cloudflare-zero-days-mail-unsubscribing-for-xss/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-160-cloudflare-zero-days-mail-unsubscribing-for-xss.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Episode 160: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn. Chat through some news, Including a Cloudflare Zero-day, Turning List-Unsubscribe into an SSRF/XSS Gadget, & Magic String Denial of Service in Claude. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: [email protected] Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/   ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Sponsor: Adobe. Use code CTBB040126, and get a 10% bonus on your bounty for any AI vulnerability which is mapped to the OWASP LLM top 10. Valid on Adobe Acrobat Web - AI Assistant / PDF Spaces / Content Creation and presentation features using Express Adobe Express AI Assistant.  Valid through April 1st, 2026 Also we have a Google Cloud VRP Swag Bonus! Mention the podcast in any rewarded (cash or credit) VRP report submission before the end of April to receive bonus swag! ====== Resources ====== Cloudflare Zero-day https://fearsoff.org/research/cloudflare-acme Turning List-Unsubscribe into an SSRF/XSS Gadget https://security.lauritz-holtmann.de/post/xss-ssrf-list-unsubscribe/ Breaking Multi-Tenant Isolation in Heroku Postgres https://allistair.sh/blog/breaking-heroku-postgres/ Parse and Parse: MIME Validat…