When a Password Reset Is Not Enough: Discovering Inconsistent Session Revocation in Galaxus
A session cookie rejected by the token refresh endpoint continued to be accepted by a GraphQL mutation endpoint for 20 minutes after password reset — here's how I found it, proved it, and reported it.
Security Research