
http-request-smuggling
CLI tool to detect HTTP Request Smuggling vulnerabilities using time-delay analysis with built-in CL.TE and TE.CL payloads for automated security…

CLI tool to detect HTTP Request Smuggling vulnerabilities using time-delay analysis with built-in CL.TE and TE.CL payloads for automated security…

Burp Suite extension for automated detection and exploitation of HTTP request smuggling vulnerabilities, supporting HTTP/1.1 and HTTP/2-downgrade…

Python-based HTTP request smuggling and desync testing tool that detects CL.TE and TE.CL vulnerabilities using configurable mutation payloads and…

HTTP Request Smuggling over HTTP/2 Cleartext (h2c)

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling…

Rust-powered HTTP Request Smuggling Scanner.

PoC and lab environment for CVE-2023-25950: HTTP request smuggling via malformed header fields in HAProxy's HTTP/3 implementation, enabling DoS and…

Multi-threaded scanner for CVE-2025-61882 in Oracle E-Business Suite, exploiting HTTP request smuggling to achieve unauthenticated remote code…

Proof-of-concept exploit for CVE-2022-22536, demonstrating HTTP request smuggling and cache poisoning against SAP NetWeaver servers to compromise…

HTTP Request Smuggling lab: Apache 2.4.55 CRLF injection

Proof-of-concept exploit for CVE-2021-40346, an integer overflow in HAProxy enabling HTTP request smuggling and potential access control bypass.

SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass…

Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)

Proof-of-concept exploit for CVE-2023-25690 HTTP Request Smuggling in Apache mod_proxy. Includes lab environment with Docker, BurpSuite walkthrough,…

PoC exploit for CVE-2021-40346: HAProxy integer overflow enabling HTTP request smuggling and ACL bypass. Includes analysis, reproduction steps, and…

Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)

Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)