
Nebula Security found CVE-2026-55493 in HotCRP, a 9-year-old vuln that could expose reviewers' identities. At minimum, it could reveal exactly who accepted or rejected your paper We also found CVE-2026-63491. Both were responsibly disclosed to Kohler. Thanks to his quick fix!
Post summary
Nebula Security identified two HotCRP CVEs that could reveal reviewer identities and responsibly disclosed them, resulting in a quick vendor patch.
