HTTP Request Smuggling - Vulnerability

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
December 4, 2025
Last Seen
August 20, 2026

HTTP Request Smuggling (HRS) is a class of vulnerabilities where crafted HTTP requests exploit desync between front-end proxies (like CDNs or load balancers) and back-end origin servers, potentially bypassing security controls, causing cache poisoning, or enabling unauthorized access.

Overview

HTTP Request Smuggling (HRS) is a class of vulnerabilities where crafted HTTP requests exploit desync between front-end proxies (like CDNs or load balancers) and back-end origin servers, potentially bypassing security controls, causing cache poisoning, or enabling unauthorized access. In the reported case, Akamai patched an HRS flaw in its Edge Servers, underscoring the ongoing risk to edge deployments and the need for prompt patching.

Related Threat Clusters

Recent Intelligence Reports

  • New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts — Gbhackers · August 20, 2026
  • Ubuntu 26.04 Cap'n Proto Important HTTP Request Smuggling Issues USN-8650 — Linuxsecurity · August 19, 2026
  • OpenWrt releases security updates for critical DHCPv6 flaw and other vulnerabilities — Scworld · July 29, 2026
  • Fedora 44 tinyproxy Important HTTP Request Smuggling Fixes 2026 — Linuxsecurity · June 27, 2026
  • Fedora 43 tinyproxy Important HTTP Request Smuggling Fix 2026 — Linuxsecurity · June 27, 2026
  • Mageia 9 perl-Starman Important HTTP Request Smuggling MGASA-2026 — Linuxsecurity · May 7, 2026
  • Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 – James Kettle – ASW #380 — Scworld · April 28, 2026
  • Fixing request smuggling vulnerabilities in Pingora OSS deployments — Blog.Cloudflare · March 9, 2026

CVSS v3.1 Breakdown