A Trailing Slash Bypassed AWS API Gateway Authorization

General News

Summary

A researcher found that adding a trailing slash to AWS HTTP API routes could bypass Lambda authorizer checks and expose protected endpoints. The issue let unauthorized requests return account data and even initiate a wire transfer in the reproduced fintech example. The root cause was a mismatch between route matching and authorization handling, combined with backend code that trusted authorizer context without validating it independently. The article advises teams to test trailing-slash variants, harden Lambda validation, and consider REST API for stricter path matching on sensitive endpoints.

Classifications

industries
Entertainment
applications
Anti Piracy

AskAI Classifications

Labels
SaaS Shipping Software Inventory Management Software

Linked Companies

Amazon
$1B+