HTTP Request Smuggling, Explained: When Two Servers Disagree on Where a Request Ends
Request smuggling hides one HTTP request inside another by exploiting a front end and back end that frame the same bytes differently. Here is how CL.TE, TE.CL, TE.TE, CL.0 and HTTP/2 downgrades work, how to test for them safely, and how to make every hop agree.