ended3월 31일· 1 sources

Railway's CDN Misconfiguration Leaks Authenticated User Data to Unauthorized Users

Railway의 CDN 설정 오류, 인증 사용자 데이터 무단 노출

Why it matters

A critical bug in Railway's CDN system accidentally enabled caching for disabled domains for 52 minutes on March 30, 2026, exposing authenticated user data to unauthorized users across ~0.05% of affected domains. This incident underscores the security risks inherent in multi-tenant cloud infrastructure, where configuration errors can inadvertently breach user privacy and data confidentiality. Railway has implemented additional safeguards and prioritized security over feature development to prevent similar incidents.

1
Sources
+0
24h
Growth
162d
Active
RailwayCDN cachingdata exposureauthentication bypasscache misconfiguration

Sources

Related Issues