2 years ago
Someone found a vulnerability that leads to a DoS attack on my api, but I suspect it's Railway related. Can someone contact on DM? Or is there a better place to disclose this?
21 Replies
2 years ago
may i ask what makes you think this is railway related?
Application still runs, doesn't crash and doesn't appear to use all available resources, but requests fail with CORS error, while the malicious requests are running
2 years ago
what status code though?
2 years ago
may you tell me the status code please
2 years ago
seems like your app has soft locked with all this traffic
2 years ago
at this time, im not seeing any issues with railway itself
2 years ago
that was what i thought, seems like a softlock
2 years ago
what kind of app is this
2 years ago
do you have cloudflare in front?
2 years ago
thats what cloudflare's main selling point is
If you’re concerned this is a platform issue please provide as much info as possible to security@railway.app for triage

