Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining. This is usually a false positive, but sometimes there's actually a real
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | HTTP/1.1 must die: the desync endgame | -5 | 7 | 06-08-2025 |
| 2 | The Fragile Lock: Novel Bypasses For SAML Authentication | 0 | 8 | 10-12-2025 |
| 3 | Анатомия HTTP Request Smuggling | 0 | 6.59 | 12-08-2026 |
| 4 | CRLF-Powered Desync Attacks: Beheading HTTP Streams | 0 | 17.16 | 05-08-2026 |
| 5 | spoof: A Simple HTTP Server for Test Environments | 0 | 10 | 11-06-2026 |
| 6 | Introducing HTTP Anomaly Rank | 0 | 5 | 11-11-2025 |
| 7 | Inline Style Exfiltration: leaking data with chained CSS conditionals | 5 | 8 | 26-08-2025 |
| 8 | HTTP/2 Bomb: Why Linux Infrastructure is Vulnerable to a New Low-Bandwidth DoS Attack | 0 | 8 | 04-06-2026 |
| 9 | Cookie Chaos: How to bypass __Host and __Secure cookie prefixes | 0 | 7 | 03-09-2025 |
| 10 | WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine | 0 | 7 | 17-09-2025 |