Auth BypassCVSS 8.6high
5 min read
The Trailing Slash That Bypassed Authentication
Adding a single character to the end of a URL turned a 401 into a 200. Not on one endpoint — on thirty, across ten microservices. One slash, an entire backend unlocked.
Read case