Top 10 winner
HTTP/2: The Sequel is Always Worse
HTTP/2 front-ends that downgrade requests to HTTP/1.1 lose the binary length field, so the back-end must trust an attacker-supplied Content-Length or Transfer-Encoding. This gives H2.CL and H2.TE desyncs, plus header and request-line injection through newlines and colons. An attacker can hijack other users' requests, poison caches and steal credentials.
Record
- Researcher
- James Kettle
- Published by
- PortSwigger Research
- Date
- Topic
- HTTP
In the archive
Related sources
- DEF CON presentation session
- Netty advisory Advisory
- Header-discovery extension
- Research HTTP/2 implementation
- HTTP/2: The Sequel is Always Worse - James Kettle (albinowax)
- HTTP/2: The Sequel is Always Worse
- HTTP/2: The Sequel is Always Worse
Tags
This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .