
smugglex
Rust-powered HTTP Request Smuggling Scanner.

Rust-powered HTTP Request Smuggling Scanner.

HTTP Request Smuggling lab: Apache 2.4.55 CRLF injection

Burp Suite extension for automated detection and exploitation of HTTP request smuggling vulnerabilities, supporting HTTP/1.1 and HTTP/2-downgrade…

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)

Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)

Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)

PoC exploit for CVE-2021-40346: HAProxy integer overflow enabling HTTP request smuggling and ACL bypass. Includes analysis, reproduction steps, and…

Proof-of-concept demonstrating CRLF injection and HTTP request smuggling in Axios, chaining prototype pollution to achieve SSRF and access internal…

HTTP Request Smuggling

#F5-BIG-IP-CVE-2023-46747-Exploit – Unauthenticated RCE Python exploit & Nuclei template by Raguraman ✓ Automated TCP reverse shell (LHOST/LPORT)…

Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle…

CVE-2025-55315 PoC Exploit

Quick and Simple Scripts to Scan for Vulnerable Servers and Packet Level Monitors

Multi-threaded scanner for CVE-2025-61882 in Oracle E-Business Suite, exploiting HTTP request smuggling to achieve unauthenticated remote code…

PoC and lab environment for CVE-2023-25950: HTTP request smuggling via malformed header fields in HAProxy's HTTP/3 implementation, enabling DoS and…

Working exploit for CVE-2025-23167 – HTTP request smuggling in vulnerable Node.js 20.x versions before 20.19.2

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling…