0xrafasec
HomeCVE deep-divesAll articlesToolsLearningAbout
HomeCVE deep-divesAll articlesToolsLearningAbout

Articles in Web App & API Security

Filter by category

AllCVE AnalysisDecentralized Systems SecurityDetection & DefenseHardware & Firmware SecurityMalware Analysis & Reverse EngineeringMethodology & MindsetNetwork & InfrastructureNotebookTutorialsWeb App & API Security
Web App & API SecurityAdvanced
ArticleWeb App & API Security

GraphQL Alias Batching as a Rate-Limit and IDOR Bypass Primitive

GraphQL was designed to give clients power — the power to ask for exactly what they need, composed however they like, in a single round-trip. That composability is also its security paradox.

Feb 18, 2026
tutorialsecurityadvancedweb_app_security

Search

Categories

  • CVE Analysis
  • Decentralized Systems Security
  • Detection & Defense
  • Hardware & Firmware Security
  • Malware Analysis & Reverse Engineering
  • Methodology & Mindset
  • Network & Infrastructure
  • Notebook
  • Tutorials
  • Web App & API Security

Connect

0xrafasec

Security research, decoded. CVE deep-dives, vulnerability analysis, ethical hacking. No fluff.

Links

  • Home
  • All articles
  • Tools
  • Learning
  • About
  • RSS Feed

Connect

Subscribe to the newsletter

Get the latest security research and CVE analysis delivered to your inbox.

© 2026 0xrafasec. All rights reserved.