Web Hack List

Top 10 winner

HTTP Smuggling via Higher HTTP Versions

HTTP Request Smuggling via higher HTTP versions

Request smuggling against front ends that terminate HTTP/2 or HTTP/3 and forward HTTP/1.1. Because HTTP/2 header names and values are binary strings that may contain newlines and colons, and content-length and transfer-encoding are not revalidated on downgrade, an attacker can inject a second request into the backend stream. Includes detection methods and a tool.

Record

Document
HTTP Request Smuggling via higher HTTP versions
Researcher
Emil Lerner
Published by
Slideshare
Date
Format
Slides
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Emil Lerner, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .