DEV Community

API

Application Programming Interface

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

Comments
6 min read
CRLF Injection in API Responses: When User Input Reaches HTTP Headers

CRLF Injection in API Responses: When User Input Reaches HTTP Headers

Comments
5 min read
NoSQL Injection in APIs: From Auth Bypass to JavaScript Execution via MongoDB Operators

NoSQL Injection in APIs: From Auth Bypass to JavaScript Execution via MongoDB Operators

Comments
5 min read
Nine things I measured about the HubSpot API that the docs don't tell you

Nine things I measured about the HubSpot API that the docs don't tell you

1
Comments
6 min read
Prompt Caching Is a Timing Oracle: How the 41-80% Cost Win Becomes Cross-Tenant System Prompt Extraction

Prompt Caching Is a Timing Oracle: How the 41-80% Cost Win Becomes Cross-Tenant System Prompt Extraction

Comments
4 min read
Stop Faking Your Test Data: Why `Faker.js` Breaks the Moment You Have Foreign Keys

Stop Faking Your Test Data: Why `Faker.js` Breaks the Moment You Have Foreign Keys

Comments
5 min read
Non-Constant-Time Comparison Turns Every API Token into a Character-by-Character Oracle

Non-Constant-Time Comparison Turns Every API Token into a Character-by-Character Oracle

Comments
5 min read
One API Key Across OpenAI, Claude and Gemini: Chatbot Fallback Options for SaaS Apps

One API Key Across OpenAI, Claude and Gemini: Chatbot Fallback Options for SaaS Apps

Comments
7 min read
The most dangerous API response is HTTP 200 with an empty body

The most dangerous API response is HTTP 200 with an empty body

Comments
4 min read
3 API changes to audit before your next deploy: Supabase, HubSpot, and Shopify

3 API changes to audit before your next deploy: Supabase, HubSpot, and Shopify

Comments
3 min read
GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls

GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls

Comments
5 min read
Three Signal Channels Leak Valid Account Lists Before Authentication Completes: Status Code, Response Body, and Timing

Three Signal Channels Leak Valid Account Lists Before Authentication Completes: Status Code, Response Body, and Timing

Comments
5 min read
SSRF in APIs: Six URL-Accepting Parameter Types and the IMDSv1/IMDSv2 Decision That Determines Severity

SSRF in APIs: Six URL-Accepting Parameter Types and the IMDSv1/IMDSv2 Decision That Determines Severity

Comments
5 min read
GraphQL in Production: Introspection, Alias Batching, and Rate Limit Bypass on Real APIs

GraphQL in Production: Introspection, Alias Batching, and Rate Limit Bypass on Real APIs

Comments
6 min read
A field disappeared from Shopify webhooks for two days and every monitor stayed green

A field disappeared from Shopify webhooks for two days and every monitor stayed green

Comments
9 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.