A smuggled request was stored as a cached response
The impact the program described is a poisoned cache. The weakness label is smuggling. Report the mechanism you measured. This card does not repeat a smuggling sequence.
- Original severity
- High (8.7) source-reported; not rescored by vulns.co
- Public source
- hackerone disclosure
- Program / vendor
- PayPal
- Product / surface
- Frontend cache in front of paypal.com
- Weakness
- HTTP request smuggling
- Affected boundary
- A cached response shared with later visitors, including the sign-in page
- Disclosure date
- 2019-08-07
- Public status checked
- 2026-09-28
- Public attribution
- albinowax
What the evidence established
PayPal's summary says a request-smuggling issue in the caching tier stored a redirect, so a later visitor could receive the researcher's cached content. They reported no evidence of real-world attacks. The listed weakness is HTTP request smuggling.
Why the impact was credible
The source reported that a cached response could replace a page the next visitor requested, including a sign-in page. Back-end data was not changed.
Durable engineering lesson
The impact the program described is a poisoned cache. The weakness label is smuggling. Report the mechanism you measured. This card does not repeat a smuggling sequence.
Control pattern
Make the proxy and the origin agree on request boundaries, and do not cache a response that was produced by a desynchronized request.
Primary public disclosure
Upstream availability and wording can change. Public status was last checked 2026-09-28.