Switch language한국어
Back to the list

I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty | Hacker News

TL;DR AI

Key summary

2 min read
  1. A security researcher found an AWS API Gateway auth bypass caused by a trailing-slash URL mismatch.

  2. By using a crafted domain and subdomain setup, the researcher was able to reach blocked endpoints.

  3. The issue shows how small URL normalization differences can lead to real authentication failures.

  4. AWS treated the report as a valid vulnerability and awarded a $12,000 bug bounty.

Read the original