HackerOne Disclosed Reports - 2026-05-05

0 Replies, 4 Views

Logo
Low
resolved

Out of scope: Improper Input Validation Order on /api-internal/login via password field leads to unnecessary resource consumption


Bug reported by was disclosed at May 5, 2026, 3:07 pm   |  

A security issue was discovered in the /api-internal/login authentication endpoint of the internal login interface of Burp Suite DAST (Enterprise). The issue was caused by improper input validation order, where the application processed user-supplied input before enforcing field-level validation. This allowed extremely large payloads in the password field to be buffered and parsed prior to rejection, resulting in unnecessary resource consumption. The application fully processed the requests before applying validation, violating the fail-fast principle.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-05-05 - by hashXploiter - 5 hours ago



Users browsing this thread: 1 Guest(s)