Tag
HTTP/2
Every HTTP/2 story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 38 · 2026
Read the issue →-
HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
The new HTTP 'QUERY' method introduces a hybrid between GET and POST that poses significant security risks to unupdated web infrastructure. Inconsistent support across proxies and frameworks could allow attackers to bypass WAF signatures and exploit caching mechanisms.
Week 36 · 2026
Read the issue →-
The Validator Can Lie: SSRF Beyond URL Validation (GitLab, Mealie, Apache ShenYu, Thumbor)
The article explores how SSRF vulnerabilities arise when the security verdict of a URL validator is not preserved through the entire request lifecycle. It identifies specific 'handoff' points where discrepancies between parsers and clients can lead to unauthorized access to internal resources.
Week 27 · 2026
Read the issue →-
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)
An audit of the OpenReception medical booking platform uncovered 16 vulnerabilities, featuring critical flaws in authorization logic. These exploits allow attackers to escalate privileges to global administrator and compromise the platform's core end-to-end encryption feature.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free