3 ms·
If you're wondering what kinds of attacks this enables, I think the primary risk is HTTP Request Smuggling https://portswigger.net/research/http-desync-attacks-
by albinowax_ 6y ago
If you're wondering what kinds of attacks this enables, I think the primary risk is HTTP Request Smuggling
https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn https://portswigger.net/research/http-desync-attacks-request...
But there's a bunch of hard-to-quantify side-risks based on corner-cases that could lead to stuff like request header injection, server-side parameter pollution, and host-header attacks. I'm excited to see what shows up.