logo

Avoiding security incidents due to request collapsing

ID: 253805df-a361-5884-9cd6-973f53f2ed0b

STIX ID: report--253805df-a361-5884-9cd6-973f53f2ed0b

Feed Name: Wiz Blog

Threat Score
50/100

Date Published: 2024-09-03

Date Updated: 2026-05-01

...
...

This report explains how web caching misconfigurations—especially Amazon CloudFront's request collapsing (request coalescing)—can unintentionally serve one user's sensitive API response to other users, causing data leakage. The author reviews multiple incidents (14 tracked, 11 in the last 4 years), shows how request collapsing can ignore Cache-Control directives, and recommends mitigations (use the managed CachingDisabled policy or set minimum TTL to 0 combined with origin Cache-Control headers) plus simultaneous-request testing to detect issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.