
Voorivex Team
We Need to Talk About CSRF Again
Two CSRF scenarios that bypass content-type-based defenses; a FastAPI quirk where a missing Content-Type means JSON, and a Chromium-only safelist entry that skipped CORS preflights and powered an Apollo Server XS-Leak (since patched).
May 10, 2026 551 2