Skip to content

Archive

Application Security

21 articles
Cybersecurity 16 Sep 2026 9 min read

HTTP Request Smuggling Starts When Intermediaries Disagree on Message Boundaries

A reverse proxy accepts an HTTP/1.1 request, decides where its body ends, and forwards traffic to an application server over a persistent connection. If the application server reaches a different boundary from the same framing information, the two components stop agreeing about which bytes belong to which request. Bytes treated as body data by one component can become the start of a new request for the other. That disagreement is the core condition behind HTTP request smuggling. The defect is not simply a malformed header, a proxy, or connection reuse in isolation. It is a parser differential across a chain in which multiple recipients interpret request framing and at least one connection carries subsequent traffic.

Cybersecurity 14 Sep 2026 7 min read

PKCE Binds an OAuth Code to the Client That Started the Flow

An OAuth authorization code can pass through a browser, an operating-system URL dispatcher, a custom application scheme, or an application link before it reaches the client that requested it. That route is convenient, but it also means possession of the returned code is not always strong evidence that the intended client received it. Proof Key for Code Exchange, usually called PKCE, changes the value of an intercepted code. Before starting the authorization request, the client creates a high-entropy secret called the code verifier. The authorization server receives a derived code challenge with the request and later requires the original verifier when the code is exchanged for tokens. A party that captures only the authorization code lacks the second value needed to complete the exchange.

Cybersecurity 14 Sep 2026 8 min read

Outbound Requests Turn Application Features Into Network Authority

A URL field can look like ordinary application input until the server acts on it. Image importers, webhook testers, document renderers, link previews, feed readers, and integration checks all have legitimate reasons to make outbound requests. The security boundary changes at the moment untrusted input influences the destination: the application is no longer processing a string; it is lending its own network position to a caller. Server-side request forgery, commonly abbreviated SSRF, emerges from that mismatch in authority. An external caller may be unable to connect to an internal service, a loopback listener, or a cloud control endpoint directly. A vulnerable server can sometimes make that connection on the caller’s behalf. Authentication at the outer application does not erase the issue. The request originates from infrastructure that downstream systems may trust for entirely separate reasons.

Cybersecurity 14 Sep 2026 6 min read

Filesystem Races Break the Link Between Checks and Use

A process checks that a path is safe, records a reassuring result, then opens the path a fraction of a second later. Those two operations can look like one security decision in source code. The filesystem sees two separate events, with an interval in which names, links, directories, mounts, or permissions may change. That interval is the basis of time-of-check to time-of-use races. The issue is not limited to unusually slow systems or large timing gaps. When an attacker can influence the relevant namespace concurrently, even a small gap can separate the object that passed a check from the object that receives the privileged operation.

Cybersecurity 14 Sep 2026 6 min read

Deserialization Can Turn Data Into Program Behavior

A serialized object can look like ordinary application data while carrying enough structure to influence which classes are instantiated, which fields receive values, and which runtime hooks execute during reconstruction. That difference matters whenever an application accepts object graphs from a browser, message queue, cache, file, or another service and treats decoding as a passive parsing operation. The dangerous cases are not defined by serialization itself. JSON decoded into a fixed record type is not equivalent to a native object stream that can name arbitrary runtime classes. The security boundary appears when attacker-controlled input can select behavior-rich types, trigger lifecycle callbacks, or assemble existing code paths into an unintended computation.

Cybersecurity 14 Sep 2026 8 min read

Content Security Policy Works Best as an Execution Boundary

Content Security Policy Works Best as an Execution Boundary A web application can escape every obvious inline-script habit and still carry a broad execution surface. A compromised analytics host, an overly permissive script source, a reused nonce, or a policy that quietly tolerates inline code can leave the browser with far more authority than the application intended. Content Security Policy, usually delivered through the Content-Security-Policy response header, gives a site a way to constrain that authority. Its strongest role is not as a filter for hostile strings. It is a browser-enforced boundary around resource loading and script execution. That distinction matters because policies built as long host allowlists often age into something much weaker than their authors expect.

Cybersecurity 13 Sep 2026 7 min read

Unsafe Deserialization Turns Data Into Program Behavior

A serialized value can look inert on the wire and become active the moment an application reconstructs it. The dangerous transition is easy to miss because the input may resemble ordinary state: fields, type names, references, collection entries, or compact binary records. Yet some serialization systems restore far more than plain data. They can select classes, invoke constructors or callbacks, rebuild object graphs, and activate framework behavior during or after decoding.

Cybersecurity 13 Sep 2026 8 min read

Outbound Requests Turn Applications Into Network Proxies

A feature that fetches a remote image can acquire far more network authority than its product description suggests. From the application host, the same HTTP client may be able to reach loopback services, private address space, cloud metadata endpoints, or administrative interfaces that are invisible from the public internet. That gap between user-visible function and server-side reach is the core security problem in server-side request forgery. The vulnerable component is not necessarily a traditional proxy. Webhook testers, document renderers, URL previewers, import tools, feed readers, media processors, and callback validators can all become request brokers when an external party influences the destination.

Cybersecurity 13 Sep 2026 7 min read

JWT Verification Fails at the Algorithm Boundary

A JSON Web Token can carry a perfectly valid signature and still be unacceptable to the service receiving it. That distinction is easy to lose in systems where token verification is reduced to a library call that returns a boolean or a decoded claims object. JWT signatures establish a narrow fact: given a particular algorithm and key, the protected token bytes authenticate successfully. Authorization requires more. The verifier also has to decide which algorithms are permitted, which keys belong to the expected authority, which issuer produced the token, which service the token targets, whether its time constraints hold, and whether this class of token is valid for the operation at hand.

Cybersecurity 13 Sep 2026 8 min read

Deserialization Can Turn Data Into Execution

Deserialization Can Turn Data Into Execution A serialized object can look like inert application state right up to the moment a runtime reconstructs it. At that boundary, a compact sequence of bytes may stop behaving like ordinary data and begin selecting classes, invoking reconstruction hooks, resolving references, allocating complex object graphs, or activating framework machinery. That distinction matters whenever serialized state crosses a trust boundary. The risky property is not simply that an attacker can submit malformed input. Many native serialization systems preserve enough information about program objects that decoding carries semantics far beyond parsing JSON fields into a plain record. In the wrong context, deserialization becomes a mechanism for asking the application to assemble behavior chosen partly by the input.

Cybersecurity 12 Sep 2026 7 min read

SSRF Controls Must Follow the Connection

A link-preview service can reject localhost, block private IPv4 ranges, accept an ordinary public hostname, and still connect to an internal address. The gap appears when validation is treated as a property of the submitted string while the actual network request is allowed to evolve after that check. Server-side request forgery, commonly shortened to SSRF, exploits that gap. The application becomes a network client acting with its own reachability, credentials, protocol support, and trust relationships. A request that looks harmless at the HTTP boundary can acquire a very different destination through name resolution or redirection before a socket is opened.

Cybersecurity 12 Sep 2026 7 min read

Prototype Pollution Turns Object Shape Into Shared State

A configuration object arrives with ordinary JSON fields, passes schema checks for the values the application expects, and is merged into defaults. Later, code in another part of the process reads a property that was never present on its own object. The value still exists. It came through the prototype chain. That separation between the write and its eventual effect is what makes prototype pollution unusually awkward to reason about. The vulnerable operation can look like routine object plumbing: recursive merge logic, path-based assignment, query parsing, or a helper that copies attacker-controlled keys. The security consequence appears only when another component treats inherited state as if it were local, trusted configuration.

Cybersecurity 12 Sep 2026 6 min read

Native Object Deserialization Expands the Trusted Computing Surface

A serialized object can look like ordinary application data at the edge of a system and behave very differently once it reaches a native object decoder. The distinction matters because some serialization mechanisms do more than parse fields. They reconstruct types, restore object graphs, resolve references, and invoke behavior associated with object creation or restoration. That capability is convenient inside a trusted boundary. Across an untrusted boundary, it can make the application’s installed code part of the input language.

Cybersecurity 12 Sep 2026 6 min read

JWT Verification Is a Policy Decision Before It Is a Crypto Check

JWT Verification Is a Policy Decision Before It Is a Crypto Check A JWT can carry a valid signature and still be unacceptable to the service receiving it. The signature proves only that the token matches a cryptographic key under a particular algorithm. It does not establish that the key belongs to an issuer the service trusts, that the algorithm is permitted for this token class, or that the claims authorize use at this endpoint.

Cybersecurity 12 Sep 2026 7 min read

Archive Extraction Is a Filesystem Security Boundary

Archive Extraction Is a Filesystem Security Boundary An archive extractor can receive a destination directory, join each stored name beneath it, and still write somewhere else. The gap appears when archive metadata is treated as harmless naming information even though extraction ultimately asks a filesystem to resolve paths, links, and object types with its own semantics. The familiar ../ traversal is only the most visible form of the problem. Absolute paths, symbolic links, hard links, platform-specific path syntax, pre-existing filesystem objects, and replacement races can all affect where a write lands. A robust design therefore cannot reduce extraction safety to a string check performed once before files are created.

Cybersecurity 11 Sep 2026 8 min read

Reject Duplicate JSON Keys at Security Boundaries

JSON looks simple enough that teams often treat parsing as a solved problem. A payload arrives, a library turns it into an object, validation runs, and the application uses the result. That model breaks when an object contains the same member name more than once. Different parsers, frameworks, gateways, signature layers, and application components can resolve duplicate names differently. One component may keep the first value, another may keep the last, and another may reject the payload. If a security decision is made using one interpretation and an action is performed using another, the gap becomes a security boundary failure.

Cybersecurity 11 Sep 2026 8 min read

Pin JWT Verification to Approved Algorithms

A JSON Web Token can carry identity and authorization claims across service boundaries. Its compact format also carries a header that describes cryptographic processing, including an alg field. That field comes from the token itself. It is attacker-controlled input until verification succeeds. A verifier therefore must not treat alg as permission to select any cryptographic mode a library happens to support. The application must decide which algorithm, key type, issuer, audience, and other verification rules are acceptable. The token may identify a candidate within that fixed policy, but it must not define the policy.

Cybersecurity 11 Sep 2026 8 min read

Encode Untrusted Data Before Writing Security Logs

Security logs often contain values that originated outside the trust boundary: usernames, request paths, HTTP headers, device names, search terms, object identifiers, and error details. Those values can be useful during incident response, but they can also become an attack surface when an application inserts them into log records without safe encoding. A malicious value containing line breaks or terminal control data can distort a text log, create a record that appears to come from the application, or make an analyst misread the sequence of events. The same input can also cause trouble farther downstream when collectors and parsers disagree about record boundaries.

Cybersecurity 11 Sep 2026 9 min read

Design Shared Cache Keys Around Response Variance

Shared HTTP caches can reduce latency and origin load, but they also introduce a security boundary. A cache stores a response produced for one request and may later serve that response to another request. That reuse is correct only when both requests are equivalent for every property that can affect the response. A dangerous configuration appears when an origin varies its response on a request property that the shared cache does not include in cache selection. An attacker can send a crafted request, cause the origin to generate attacker-influenced content, and leave that content stored under a key that ordinary visitors also use.

Cybersecurity 04 Sep 2026 9 min read

Make Security-Sensitive State Changes Atomic

Security checks can be individually correct and still fail when two requests run at the same time. A request checks that a recovery code is unused, a withdrawal is within a limit, or an approval is still pending. Before it records the state change, another request performs the same check against the same old state. Both requests then proceed even though the rule was meant to allow only one. This is a race condition: correctness depends on the relative timing of concurrent operations. A common form is a time-of-check to time-of-use problem, often shortened to TOCTOU, where the fact established by a check can become false before the protected action uses it.

Cybersecurity 01 Sep 2026 5 min read

Practical Threat Modeling with Trust Boundaries and Abuse Cases

Threat modeling is most useful before a vulnerability becomes a patch request. It gives a team a structured way to ask how a system can be misused, which assumptions are security-sensitive, and where defenses should exist. A useful threat model does not need to be a large document. For many services, a one-page data-flow sketch plus a prioritized set of abuse cases is enough to improve design decisions. Begin with assets and security goals Start by identifying what the system is trying to protect.