<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Plentex Blog</title>
    <link>https://plentex.app/blog</link>
    <description>Security research and engineering write-ups from Plentex.</description>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://plentex.app/blog/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>One path, two interpretations: a route-level authorization bypass</title>
      <link>https://plentex.app/blog/843219830</link>
      <guid isPermaLink="true">https://plentex.app/blog/843219830</guid>
      <pubDate>Thu, 08 Oct 2026 00:00:00 GMT</pubDate>
      <description>A local case study of an authorization bypass caused by route matching and resource lookup using different URL path representations.</description>
      <dc:creator>Logan Treloar</dc:creator>
      <category>Research</category>
      <category>web security</category>
      <category>authorization</category>
      <category>routing</category>
    </item>
  </channel>
</rss>
