HTTP Request Smuggling (HRS) is a class of vulnerabilities where crafted HTTP requests exploit desync between front-end proxies (like CDNs or load balancers) and back-end origin servers, potentially bypassing security controls, causing cache poisoning, or enabling unauthorized access.
Overview
HTTP Request Smuggling (HRS) is a class of vulnerabilities where crafted HTTP requests exploit desync between front-end proxies (like CDNs or load balancers) and back-end origin servers, potentially bypassing security controls, causing cache poisoning, or enabling unauthorized access. In the reported case, Akamai patched an HRS flaw in its Edge Servers, underscoring the ongoing risk to edge deployments and the need for prompt patching.
Related Threat Clusters
-
Critical HTTP Request Smuggling Vulnerability in Starman Web Server
A critical vulnerability has been identified in Starman versions prior to 0.4018, allowing HTTP Request Smuggling due to improper header precedence. The issue arises when both 'Content-Length' and 'Transfer-Encoding:…
4 articles · Updated May 8, 2026 -
Critical HTTP Request Smuggling Vulnerabilities in Fedora Tinyproxy
On June 18, 2026, Fedora released updates for tinyproxy addressing two critical HTTP Request Smuggling vulnerabilities, CVE-2026-54387 and CVE-2026-54388, both published on June 17, 2026. These vulnerabilities affect…
2 articles · Updated June 27, 2026 -
OpenWrt Releases Critical Security Updates for DHCPv6 Vulnerabilities
OpenWrt has released updates for versions 24.10.8 and 25.12.5 to address critical security vulnerabilities. The most severe issue is a buffer overflow in the odhcpd DHCP server, allowing unauthenticated attackers to…
4 articles · Updated July 29, 2026 -
Critical HTTP Request Smuggling Vulnerabilities in Cap'n Proto
Two vulnerabilities (CVE-2026-32239, CVE-2026-32240) in Cap'n Proto were discovered by Chanho Kim and Jihyeok Han, allowing attackers to exploit improper handling of negative Content-Length values and large chunk sizes…
2 articles · Updated August 19, 2026 -
CRLF-Powered Desync Attacks Enable Account Hijacking and Cookie Theft
Security researchers have identified a new category of HTTP request smuggling attacks termed 'CRLF-Powered Desync Attacks.' These attacks exploit a CRLF injection vulnerability, allowing attackers to hijack user…
2 articles · Updated August 20, 2026 -
Cloudflare Pingora Vulnerabilities Enable Request Smuggling Attacks
Cloudflare identified and patched HTTP/1.x request smuggling vulnerabilities in the Pingora open source framework. These vulnerabilities, reported through their Bug Bounty Program, are tracked as CVE-2026-2833,…
3 articles · Updated March 10, 2026 -
Insights on 2025 Web Hacking Techniques and LLM Impact for 2026
James Kettle from PortSwigger discusses the top web hacking techniques of 2025 and anticipates the influence of large language models (LLMs) on future vulnerabilities. He emphasizes the importance of having a robust…
2 articles · Updated April 28, 2026 -
Akamai Addresses HTTP Request Smuggling Vulnerability in Edge Servers
Akamai has patched a critical HTTP request smuggling vulnerability affecting its edge servers. This flaw could potentially allow attackers to manipulate requests and bypass security measures. Users of Akamai's edge…
3 articles · Updated December 4, 2025
Recent Intelligence Reports
- New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts — Gbhackers · August 20, 2026
- Ubuntu 26.04 Cap'n Proto Important HTTP Request Smuggling Issues USN-8650 — Linuxsecurity · August 19, 2026
- OpenWrt releases security updates for critical DHCPv6 flaw and other vulnerabilities — Scworld · July 29, 2026
- Fedora 44 tinyproxy Important HTTP Request Smuggling Fixes 2026 — Linuxsecurity · June 27, 2026
- Fedora 43 tinyproxy Important HTTP Request Smuggling Fix 2026 — Linuxsecurity · June 27, 2026
- Mageia 9 perl-Starman Important HTTP Request Smuggling MGASA-2026 — Linuxsecurity · May 7, 2026
- Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 – James Kettle – ASW #380 — Scworld · April 28, 2026
- Fixing request smuggling vulnerabilities in Pingora OSS deployments — Blog.Cloudflare · March 9, 2026