topic
Verified 2026-09-18HTTP Request Smuggling and Message Framing
Request smuggling exploits disagreement between intermediaries about where an HTTP message ends.
Normalize and reject ambiguous framing, follow the HTTP version’s parsing rules, remove hop-by-hop fields at proxy boundaries, and keep front-end and back-end parsers aligned.
httpsecurityproxyframing
Reference (http)
Content-Length: 4 Transfer-Encoding: chunked
Normalize and reject ambiguous framing, follow the HTTP version’s parsing rules, remove hop-by-hop fields at proxy boundaries, and keep front-end and back-end parsers aligned.
Common mistakes
- Accepting conflicting Content-Length and Transfer-Encoding values or forwarding them unchanged.