HeadlinesBriefing favicon HeadlinesBriefing.com

Railway Security Breach Exposes User Data

Hacker News •
×

Railway experienced a security incident where CDN caching was accidentally enabled for domains with disabled settings. During 52 minutes on March 30, 2026, potentially authenticated user data was cached and served to unauthenticated users. This affected approximately 0.05% of Railway domains, causing applications to serve one user's data to another.

The configuration update deployed by a Railway engineer at 10:42 UTC caused responses without explicit cache headers to be cached. Internal monitoring detected the issue at 11:14 UTC, and the team reverted the change and purged all cached assets globally by 11:34 UTC. While Origin Cache-Control directives were respected, the incident exposed authenticated data.

Railway has notified affected users via email and implemented additional testing protocols. The company has adopted more gradual CDN rollouts over hours instead of minutes. Railway acknowledged the error, stating they will prioritize safety over new features to rebuild trust with users.