WhisperX tag archive

#gateway vulnerability

This page collects WhisperX intelligence signals tagged #gateway vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-07 17:31:41 · GitHub Issues

1. Critical Authorization Gap in Gateway Enables Cross-User Session Hijacking

A critical security flaw has been identified in the WebSocket gateway module responsible for session reconnection handling. The vulnerability exists in `internal/gateway/conn.go`, which manages the AEP init handshake for WebSocket connections. During session reconnection, when a client provides an existing `session_id`...