HTTP Smuggling Desync

HTTP request smuggling, HTTP/2 desync attacks, and parser differential vulnerabilities. Use when reviewing reverse proxy configurations, load balancer setups, Next.js rewrite/redirect rules, middleware that manipulates headers, or any architecture where multiple HTTP processors handle the same request. Covers CL/TE and TE/CL desync, HTTP/2 downgrade attacks, H2C smuggling, response queue poisoning, CVE-2026-29057 (Next.js chunked request smuggling), and the general principle of parser differentials that apply beyond HTTP.

nickgallick 9f816b3 8.1 KB Updated 0 repo stars

File contents

nickgallick/perlantir-fleet/tree/main/workspace-forge/skills/http-smuggling-desync commit 9f816b3f16

Frequently asked questions

npx skillmds add nickgallick/http-smuggling-desync