Collected research
Cache poisoning in popular open source packages
Snyk found cache-poisoning primitives in popular web frameworks caused by disagreement with reverse proxies over semicolon-separated query parameters and GET request bodies. These parser differentials let attackers override or inject unkeyed parameters into cached responses, potentially converting reflected XSS into stored attacks; matching cache keys and parsers mitigates the issue.
Record
- Researcher
- Adam Goldschmidt
- Published by
- Snyk
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adam Goldschmidt, first published at the original source. Preserved copies are kept so the citation survives its host.