ended5월 26일· 1 sources

The $12,000 Trailing Slash: How a Single Character Bypassed AWS Auth

슬래시 한 번에 보안 붕괴... AWS API Gateway 우회로 챙긴 1,200만 원 포상금

Why it matters

This vulnerability highlights a critical disconnect between AWS HTTP API's path matching logic and authorizer context handling, which can lead to catastrophic data leaks. It serves as a stark reminder that security should never rely solely on gateway-level checks but must be enforced consistently throughout the backend microservices.

1
Sources
+0
24h
Growth
118d
Active
AWS API GatewayHTTP APILambda authorizerTrailing SlashBug BountyJWT

Sources

Related Issues