PortSwigger Research disclosed an AI-assisted system called HTTP Terminator that autonomously generated, tested, and weaponized novel HTTP desynchronization and request smuggling techniques against authorized live targets. The pipeline, published on GitHub as a multi-stage research framework, reportedly produced tens of thousands of candidate vectors from RFC-derived fragments and led to multiple real-world findings, including new desync triggers, a dual-matching Content-Length desync pattern, a dangling-byte weaponization method to improve response queue poisoning, and evidence of a possible new class dubbed response forking. The work also uncovered and helped patch Apache Traffic Server zero-day CVE-2026-63078, while exposing exploitable issues involving F5 Big-IP, BeyondTrust Secure Remote Access, Citrix NetScaler, and some Azure Application Gateway plus Akamai deployments.
A related PortSwigger paper detailed CRLF-powered desync attacks that turn HTTP header injection in misconfigured Nginx, OpenResty, and Tengine environments into request smuggling, response queue poisoning, browser-powered desync, and even self-propagating desync worms. The researchers said these browser-compatible attacks can enable XSS, account takeover, token and cookie theft, and cross-user compromise across sectors including CDN, telecom, payments, retail, streaming, and social platforms. Recommended mitigations included avoiding unsafe use of $uri or $document_uri in proxy_pass or return directives, reviewing upstream proxy configurations, and enabling HTTP/2 upstream where possible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Tom Stacey and Tobia Righi published research showing how CRLF/header injection in misconfigured Nginx-based deployments can be escalated into request smuggling, response queue poisoning, browser-powered desync, and self-propagating desync worms. The paper included multiple real-world case studies across CDN, telecom, payment, retail, streaming, social media, and account-management environments.
James Kettle of PortSwigger Research published the HTTP Terminator research describing an autonomous AI-assisted system for inventing, evaluating, and weaponizing novel HTTP desynchronization attacks against authorized live targets. The work reported new desync triggers, a dangling-byte weaponization technique, evidence of response forking, and the broader Shared Parser Confusion concept.
PortSwigger published the HTTP Terminator companion repository on GitHub, exposing the four-stage AI-assisted pipeline named seeker, flamer, validator, and investigator. The repository was presented as a reference companion to the research and excluded real target data and local SQLite databases.
Apache Traffic Server patched a zero-day desynchronization flaw that PortSwigger's research had uncovered using a trigger involving DELETE, Content-Location, Max-Forwards: 0, and a TRACE payload. The issue was tracked as CVE-2026-63078.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceportswigger.net
Open sourceportswigger.net
Open sourceportswigger.net
Open sourceportswigger.net
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.