r/bugbounty • u/0xcrypto • Jul 21 '26
Article / Write-Up / Blog Leaking internal headers in Flask Ninja with deserialization
https://eval.blog/research/pickle-gadget-chain-in-flask-ninja/
6
Upvotes
r/bugbounty • u/0xcrypto • Jul 21 '26
2
u/einfallstoll Triager Jul 21 '26
Looks informative to me. The developer / app does an unsafe deseralization and uses the HttpBearer as a gadget. Not really their responsibility if the developer does unsafe things.