
CVE-2026-40175-poc
Proof-of-concept demonstrating CRLF injection and HTTP request smuggling in Axios, chaining prototype pollution to achieve SSRF and access internal…

Proof-of-concept demonstrating CRLF injection and HTTP request smuggling in Axios, chaining prototype pollution to achieve SSRF and access internal…

HTTP Request Smuggling

Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle…

Proof-of-concept exploit for CVE-2020-35669 demonstrating HTTP request smuggling and header injection in Dart's http package via crafted method…

Working exploit for CVE-2025-23167 – HTTP request smuggling in vulnerable Node.js 20.x versions before 20.19.2

Proof-of-concept exploit for CVE-2019-20372: HTTP request smuggling via nginx error_page directive, enabling access to hidden resources.

Proof-of-concept for CVE-2021-40346, demonstrating HTTP request smuggling in HAProxy via integer overflow, with Docker-based environment to bypass…

Proof-of-concept exploit for HTTP request smuggling vulnerability CVE-2020-25613, demonstrating chunked transfer encoding parsing bypass to poison…

PoC of HTTP Request Smuggling in nodejs (CVE-2020-8287)

Http request smuggling vulnerability scanner

CVE-2025-55315 PoC Exploit

exploit CVE-2024-40725 (Apache httpd) with

#F5-BIG-IP-CVE-2023-46747-Exploit – Unauthenticated RCE Python exploit & Nuclei template by Raguraman ✓ Automated TCP reverse shell (LHOST/LPORT)…

Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

Proof-of-concept exploit for CVE-2021-40438, an SSRF vulnerability in Apache HTTP Server, demonstrating request smuggling and internal network access.

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…