Skip to content

Archive

Protocol Security

2 articles
Cybersecurity 19 Sep 2026 6 min read

HTTP/1.1 Framing Disagreement Creates a Request Smuggling Boundary

HTTP/1.1 Framing Disagreement Creates a Request Smuggling Boundary An HTTP/1.1 connection can carry multiple requests in sequence. Each recipient therefore has to decide exactly where one request ends before it can parse the next. In a direct client-to-origin connection, one parser makes that decision. In a deployment with a reverse proxy, gateway, load balancer, cache, or other intermediary, the same byte stream can cross several parsers before reaching application code.

Cybersecurity 17 Sep 2026 8 min read

HTTP Request Smuggling Begins at a Message-Framing Disagreement

HTTP Request Smuggling Begins at a Message-Framing Disagreement A reverse proxy can validate an HTTP request, route it to an approved application, and still deliver a different request sequence from the one it believed it accepted. The failure does not require the proxy to ignore authentication or the origin to execute malformed syntax. It can arise when the two HTTP processors disagree about the byte at which one request ends and the next begins.