A Trailing Slash Bypassed AWS API Gateway Authorization
Summary
A researcher found that adding a trailing slash to AWS HTTP API routes could bypass Lambda authorizer checks and expose protected endpoints. The issue let unauthorized requests return account data and even initiate a wire transfer in the reproduced fintech example. The root cause was a mismatch between route matching and authorization handling, combined with backend code that trusted authorizer context without validating it independently. The article advises teams to test trailing-slash variants, harden Lambda validation, and consider REST API for stricter path matching on sensitive endpoints.
Classifications
industries
Entertainment
applications
Anti Piracy
AskAI Classifications
Labels
SaaS
Shipping Software
Inventory Management Software
Linked Companies
Amazon
$1B+