Avoiding security incidents due to request collapsing
ID: 253805df-a361-5884-9cd6-973f53f2ed0b
STIX ID: report--253805df-a361-5884-9cd6-973f53f2ed0b
Feed Name: Wiz Blog
This report explains how web caching misconfigurations—especially Amazon CloudFront's request collapsing (request coalescing)—can unintentionally serve one user's sensitive API response to other users, causing data leakage. The author reviews multiple incidents (14 tracked, 11 in the last 4 years), shows how request collapsing can ignore Cache-Control directives, and recommends mitigations (use the managed CachingDisabled policy or set minimum TTL to 0 combined with origin Cache-Control headers) plus simultaneous-request testing to detect issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
