Vulnerability field guide
HTTP Request Smuggling
Request smuggling hides one HTTP request inside another by exploiting a front end and back end that frame the same bytes differently. Here is how CL.TE, TE.CL, TE.TE, CL.0 and HTTP/2 downgrades work, how to test for them safely, and how to make every hop agree.
1 article 8 min total Overview to advanced techniques