Top 10 winner
Unveiling TE.0 HTTP Request Smuggling: Discovering a Critical Vulnerability in Thousands of Google Cloud Websites
Introduces TE.0 request smuggling, where the front end honours chunked Transfer-Encoding but the back end treats the body as empty, the chunked counterpart of CL.0. Against Google Cloud Load Balancers left on HTTP/1.1, a smuggled prefix redirected live users to an attacker server and captured their session tokens.
Record
- Researcher
- Paolo Arnolfo and Guillermo Gregorio
- Published by
- Bugcrowd
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Paolo Arnolfo and Guillermo Gregorio, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .