vulns.co
/
GKData.io MCP

Back to Reports

A smuggled request was stored as a cached response

The impact the program described is a poisoned cache. The weakness label is smuggling. Report the mechanism you measured. This card does not repeat a smuggling sequence.

Editorial decision card. This page links to a source-verified public disclosure and contains only original defensive analysis. It does not mirror upstream HTML, payloads, attachments, private submissions, or exploit steps.
Original severity
High (8.7) source-reported; not rescored by vulns.co
Public source
hackerone disclosure
Program / vendor
PayPal
Product / surface
Frontend cache in front of paypal.com
Weakness
HTTP request smuggling
Affected boundary
A cached response shared with later visitors, including the sign-in page
Disclosure date
2019-08-07
Public status checked
2026-09-28
Public attribution
albinowax

What the evidence established

PayPal's summary says a request-smuggling issue in the caching tier stored a redirect, so a later visitor could receive the researcher's cached content. They reported no evidence of real-world attacks. The listed weakness is HTTP request smuggling.

Why the impact was credible

The source reported that a cached response could replace a page the next visitor requested, including a sign-in page. Back-end data was not changed.

Durable engineering lesson

The impact the program described is a poisoned cache. The weakness label is smuggling. Report the mechanism you measured. This card does not repeat a smuggling sequence.

Control pattern

Make the proxy and the origin agree on request boundaries, and do not cache a response that was produced by a desynchronized request.

Primary public disclosure

Read the original source ↗

Upstream availability and wording can change. Public status was last checked 2026-09-28.