Dark C0d3rs
HackerOne Disclosed Reports - 2026-02-11 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2026-02-11 (/Thread-HackerOne-Disclosed-Reports-2026-02-11)



HackerOne disclosed reports - 2026-02-11 - hashXploiter - 02-12-2026

Logo
Medium
resolved

Cache Pollution via Unkeyed GET Parameters on www.omise.co


Bug reported by Ali Toni was disclosed at February 11, 2026, 11:25 pm   |  

The CDN serving the website appeared to cache pages based on the full URL, including arbitrary query parameters, without normalizing or properly keying them. This behavior resulted in cache pollution, where the cache was filled with redundant versions of the same page.