Preliminary research
Can AI do novel security research? Meet the HTTP Terminator
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Feeding 1-3 sentence RFC fragments to an LLM generated 30,000 desync vectors, each validated on live sites by sending a plain request over a separate connection and watching for a changed response. It found triggers such as Content-Type: multipart/byteranges and Transfer-Encoding: gzip, the dangling-byte trick that makes response queue poisoning race-free, and Shared-Parser Confusion: servers reuse response-parsing code for requests, so response-only rules fire on a request.
Record
- Researcher
- James Kettle
- Published by
- PortSwigger Research
- Date
- Topic
- HTTP
In the archive
Related sources
- Can AI do novel security research? Meet the HTTP Terminator (Whitepaper) Whitepaper
- Tool Repository
- HTTP Request Smuggler integration
- Turbo Intruder MCP interface
- Param Miner protocol-ruler integration
Tags
This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .