
OtherCVSS 2.5€0
Out of scope: Improper Input Validation Order on /api-internal/login via password field leads to unnecessary resource consumption
bereza4321
Disclosed on HackerOne · May 5, 2026
Publicly disclosed report · by bereza4321
View original on HackerOneImproper Input Validation Order (CWE-20) in Authentication Endpoint
Type: Architectural Security Issue
CWE: CWE-20 – Improper Input Validation
Severity: High
Summary
The /api-internal/login authentication endpoint in Burp Suite DAST (Enterprise) internal login interface (test instance) processes user-supplied input before enforcing field-level validation, allowing extremely large payloads in the password field to be buffered and parsed prior to rejection. Domain intentionally omitted for confidentiality.