Web Hack List

Preliminary research

Can AI do novel security research? Meet the HTTP Terminator

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Feeding 1-3 sentence RFC fragments to an LLM generated 30,000 desync vectors, each validated on live sites by sending a plain request over a separate connection and watching for a changed response. It found triggers such as Content-Type: multipart/byteranges and Transfer-Encoding: gzip, the dangling-byte trick that makes response queue poisoning race-free, and Shared-Parser Confusion: servers reuse response-parsing code for requests, so response-only rules fire on a request.

Record

Researcher
James Kettle
Published by
PortSwigger Research
Date
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .