#RequestSmuggling
More details and official guidance from #Microsoft here:
buff.ly/QHRV8ht
Patch promptly to reduce exposure to #RequestSmuggling attacks.
#SoftwareSecurity #Developers #PatchManagement #CyberSecurity
🧵5/5
October 24, 2025 at 9:08 PM
Netty: CVE-2025-58056 request smuggling via chunk extension parsing (“funky chunks”). 4.1.124.Final and 4.2.0.Alpha1–4.2.4.Final impacted. Apply patched Netty release. Normalize requests at proxies. Disable legacy chunk extension handling. #Netty #Java #HTTP #RequestSmuggling #CVE 🧵3/5
4.1.124.Final
September 10, 2025 at 2:42 PM
A CRLF desync flaw lets attackers poison CDNs and serve live XSS via %0d%0a misuse in proxies. #CRLF #DesyncAttack #CDNSecurity #XSS #RequestSmuggling #WebSecurity thedailytechfeed.com/crlf-powered...
August 20, 2026 at 5:22 PM
Critical vulnerabilities in Apache Traffic Server (CVE-2025-58136 & CVE-2025-65114) can lead to DoS and request smuggling attacks. Upgrade to the latest versions now! #CyberSecurity #ApacheTrafficServer #DoS #RequestSmuggling Link: thedailytechfeed.com/apache-traff...
April 7, 2026 at 2:12 PM
Funky Chunks: Abusing Chunk Line Terminators for Request Smuggling

Investigates ambiguous chunk-line terminators enabling HTTP request smuggling via non-standard chunk parsing.

https://w4ke.info/2025/06/18/funky-chunks.html

#RequestSmuggling #HTTPParsing
June 21, 2025 at 5:30 AM
~Akamai~
Akamai patched a vulnerability (CVE-2026-26365) that could allow HTTP request smuggling via improper processing of custom hop-by-hop headers.
-
IOCs: (None identified)
-
#CVE202626365 #RequestSmuggling #ThreatIntel
Akamai Fixes HTTP Request Smuggling Vuln
www.akamai.com
February 24, 2026 at 4:01 AM