
CybersecurityCriticalBreaking
Trailing Slash Bypassed AWS Authentication
A security researcher discovered that adding a trailing slash to AWS HTTP API paths could bypass Lambda authorizer authentication entirely. This critical vulnerability, caused by a path normalization mismatch, enabled unauthorized actions, including wire transfers at a fintech company, highlighting a significant security risk.
InfoQ1 min read