⤷ Title: Request Splitting: Exploiting the Request Headers
════════════════════════
𐀪 Author: Geni_Wazir
════════════════════════
ⴵ Time: Wed, 05 Feb 2025 17:42:32 GMT
════════════════════════
⌗ Tags: #hacking #request_smuggling #http_request #cybersecurity #testing
════════════════════════
𐀪 Author: Geni_Wazir
════════════════════════
ⴵ Time: Wed, 05 Feb 2025 17:42:32 GMT
════════════════════════
⌗ Tags: #hacking #request_smuggling #http_request #cybersecurity #testing
Medium
Request Splitting: Exploiting the Request Headers
What is Request Splitting?
⤷ Title: CLZero: fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Feb 2025 01:10:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Web AppSec #CLZero #Request Smuggling Attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Feb 2025 01:10:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Web AppSec #CLZero #Request Smuggling Attack
Penetration Testing Tools
CLZero: fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors
CLZero is a project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors.Inspired by the tool Smuggler all attack gadgets adapted from Smuggler
⤷ Title: Understanding Request Smuggling: A Sneaky Vulnerability and How to Test It
════════════════════════
𐀪 Author: Tanouhabib
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 21:45:12 GMT
════════════════════════
⌗ Tags: #request_smuggling #cybersecurity #penetration_testing #portswigger #web_vulnerabilities
════════════════════════
𐀪 Author: Tanouhabib
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 21:45:12 GMT
════════════════════════
⌗ Tags: #request_smuggling #cybersecurity #penetration_testing #portswigger #web_vulnerabilities
Medium
Understanding Request Smuggling: A Sneaky Vulnerability and How to Test It
Subtitle (optional): “Explore the mechanics, real-world examples, and a practical lab to master this critical web attack.”
⤷ Title: Apache Traffic Server Hit by Request Smuggling Vulnerability (CVE-2024-53868)
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 04 Apr 2025 00:36:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache Traffic Server #CVE_2024_53868 #Request Smuggling Attack
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 04 Apr 2025 00:36:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache Traffic Server #CVE_2024_53868 #Request Smuggling Attack
Daily CyberSecurity
Apache Traffic Server Hit by Request Smuggling Vulnerability (CVE-2024-53868)
Understand CVE-2024-53868: a vulnerability in Apache Traffic Server that affects how chunked messages are processed.
⤷ Title: CVE-2025-43859: Request Smuggling Vulnerability in Python’s h11 HTTP Library
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 27 Apr 2025 00:06:35 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_43859 #CVSS 9.1 #h11 #HTTP vulnerability #Python #request smuggling #reverse proxy #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 27 Apr 2025 00:06:35 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_43859 #CVSS 9.1 #h11 #HTTP vulnerability #Python #request smuggling #reverse proxy #Web Security
Daily CyberSecurity
CVE-2025-43859: Request Smuggling Vulnerability in Python’s h11 HTTP Library
A CVE-2025-43859 vulnerability in Python’s h11 library may lead to request smuggling attacks when paired with buggy proxies. Patch to version 0.15.0 now.
⤷ Title: Bypassing OTP: Unlocking Vulnerabilities & Securing Your App
════════════════════════
𐀪 Author: B4LOGI
════════════════════════
ⴵ Time: Thu, 01 May 2025 06:03:43 GMT
════════════════════════
⌗ Tags: #request #responses #otp_bypass #cybersecurity #infosec
════════════════════════
𐀪 Author: B4LOGI
════════════════════════
ⴵ Time: Thu, 01 May 2025 06:03:43 GMT
════════════════════════
⌗ Tags: #request #responses #otp_bypass #cybersecurity #infosec
Medium
🔓 Bypassing OTP: Unlocking Vulnerabilities & Securing Your App 💻🔐
While logged into a web application, you’ve probably received an OTP (One Time Password) on your phone or email. It’s supposed to be an…
⤷ Title: Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:50:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:50:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
Daily CyberSecurity
Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
Varnish Cache and Enterprise have a vulnerability allowing HTTP request smuggling. This can lead to cache poisoning and WAF bypass. Upgrade now!
⤷ Title: HTTP/1.1 Must Die: Why This 6-Year-Old Vulnerability Is Still a Major Threat
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 08:49:04 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #HTTP/1.1 #HTTP/2 #PortSwigger #Request Smuggling #vulnerability #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 08:49:04 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #HTTP/1.1 #HTTP/2 #PortSwigger #Request Smuggling #vulnerability #web security
Penetration Testing Tools
HTTP/1.1 Must Die: Why This 6-Year-Old Vulnerability Is Still a Major Threat
A 6-year-old flaw in the HTTP/1.1 protocol still enables critical request smuggling attacks. Experts are now calling for its complete and unconditional retirement.
⤷ Title: HTTP Request Smuggling: Basic CL.TE Vulnerability
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 14 Aug 2025 15:31:17 GMT
════════════════════════
⌗ Tags: #bug_bounty #clte_vulnerability #http_request_smuggling #request_smuggling #chunked_transfer_encoding
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 14 Aug 2025 15:31:17 GMT
════════════════════════
⌗ Tags: #bug_bounty #clte_vulnerability #http_request_smuggling #request_smuggling #chunked_transfer_encoding
Medium
HTTP Request Smuggling: Basic CL.TE Vulnerability
Learn how CL.TE request smuggling works, why it’s dangerous, and how attackers exploit server parsing differences.
⤷ Title: HTTP Request Smuggling: Basic CL.TE Vulnerability
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 07:25:24 GMT
════════════════════════
⌗ Tags: #bug_bounty #clte_vulnerability #http_request_smuggling #request_smuggling #chunked_transfer_encoding
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 07:25:24 GMT
════════════════════════
⌗ Tags: #bug_bounty #clte_vulnerability #http_request_smuggling #request_smuggling #chunked_transfer_encoding
Medium
HTTP Request Smuggling: Basic CL.TE Vulnerability
Learn how CL.TE request smuggling works, why it’s dangerous, and how attackers exploit server parsing differences.
⤷ Title: Critical Flaws in Hiawatha Web Server Could Allow Authentication Bypass and RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:16:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #cybersecurity #double_free #Hiawatha #open_source #rce #request smuggling #Vulnerability #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:16:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #cybersecurity #double_free #Hiawatha #open_source #rce #request smuggling #Vulnerability #web server
Daily CyberSecurity
Critical Flaws in Hiawatha Web Server Could Allow Authentication Bypass and RCE
CERT/CC warns of critical flaws in the Hiawatha web server. The vulnerabilities could allow attackers to bypass authentication and hijack sessions.
⤷ Title: Aiohttp Patches Seven Vulnerabilities Including High-Severity DoS Risks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 02:23:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #aiohttp #Asyncio #CVE_2025_69224 #CVE_2025_69227 #CVE_2025_69228 #Denial of Service #dos #Infinite Loop #infosec #memory exhaustion #Python #request smuggling #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 02:23:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #aiohttp #Asyncio #CVE_2025_69224 #CVE_2025_69227 #CVE_2025_69228 #Denial of Service #dos #Infinite Loop #infosec #memory exhaustion #Python #request smuggling #web development
Daily CyberSecurity
Aiohttp Patches Seven Vulnerabilities Including High-Severity DoS Risks
Maintainers of aiohttp, the popular asynchronous HTTP client/server framework for Python, have released a sweeping security update addressing seven distinct vulnerabilities. The update, version 3.…
⤷ Title: Apache Traffic Server Patches “Double-Header” DoS and Request Smuggling Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 15:07:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Software Foundation #Apache Traffic Server #ATS #Caching #CVE_2025_58136 #CVE_2025_65114 #Denial of Service #infosec #request smuggling #security update #Web Proxy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 15:07:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Software Foundation #Apache Traffic Server #ATS #Caching #CVE_2025_58136 #CVE_2025_65114 #Denial of Service #infosec #request smuggling #security update #Web Proxy
Daily CyberSecurity
Apache Traffic Server Patches "Double-Header" DoS and Request Smuggling Flaws
Apache Traffic Server fixes two CVSS 7.5 flaws (CVE-2025-58136 & CVE-2025-65114). Prevent DoS and request smuggling—update to 10.1.2 or 9.2.13 now!
⤷ Title: CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 12 Apr 2026 17:10:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS IMDSv2 #Axios #Cloud Security #CVE_2026_40175 #Header injection #infosec #javascript #Node.js #Prototype Pollution #rce #request smuggling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 12 Apr 2026 17:10:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS IMDSv2 #Axios #Cloud Security #CVE_2026_40175 #Header injection #infosec #javascript #Node.js #Prototype Pollution #rce #request smuggling
Daily CyberSecurity
CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly
A critical CVSS 10 flaw in Axios (CVE-2026-40175) allows attackers to bypass AWS IMDSv2 and achieve RCE via header injection. Upgrade to v1.15.0 now!
⤷ Title: Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 01:00:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2026_29146 #CVE_2026_34486 #Encryption Bypass #infosec #Java security #Kubernetes Security #request smuggling #vulnerability management #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 01:00:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2026_29146 #CVE_2026_34486 #Encryption Bypass #infosec #Java security #Kubernetes Security #request smuggling #vulnerability management #web server
Daily CyberSecurity
Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat
Apache Tomcat discloses 10 vulnerabilities including encryption bypasses and Kubernetes token leaks. Upgrade now to secure your Java-based web applications.
⤷ Title: WebSphere Remote Code Execution Defended with New IBM Security Fixes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 May 2026 01:48:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_8620 #CVE_2026_8633 #IBM Security Bulletin #IBM WebSphere #Remote Code Execution #request smuggling #Software Patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 May 2026 01:48:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_8620 #CVE_2026_8633 #IBM Security Bulletin #IBM WebSphere #Remote Code Execution #request smuggling #Software Patch
Daily CyberSecurity
WebSphere Remote Code Execution Defended with New IBM Security Fixes
IBM released a critical WebSphere remote code execution update. Apply the request smuggling patch immediately to protect your server environment.
⤷ Title: Tinyproxy Request Smuggling Flaws Expose Networks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 02:12:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_54387 #CVE_2026_54388 #CVE_2026_55202 #request smuggling #Tinyproxy
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 02:12:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_54387 #CVE_2026_54388 #CVE_2026_55202 #request smuggling #Tinyproxy
Daily CyberSecurity
Tinyproxy Request Smuggling Flaws Expose Networks
Three critical Tinyproxy request smuggling vulnerabilities, including CVE-2026-54388, expose networks to severe attacks. Update your proxy servers immediately.
⤷ Title: Apache Traffic Server Fixes 38 Vulnerabilities in 9.2.15 and 10.1.4
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Traffic Server #ATS #CDN Security #CVE_2026_22068 #CVE_2026_58154 #request smuggling
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Traffic Server #ATS #CDN Security #CVE_2026_22068 #CVE_2026_58154 #request smuggling
Daily CyberSecurity
Apache Traffic Server Fixes 38 Vulnerabilities in 9.2.15 and 10.1.4
TL;DR The Apache Software Foundation fixed 38 Apache Traffic Server vulnerabilities. The patches landed in versions 9.2.15 and 10.1.4. The flaws range from request smuggling and access-control byp…