New research and vendor advisories have highlighted a broader class of HTTP desynchronization and request smuggling risks driven by parser inconsistencies in headers and chunked encoding. A PortSwigger paper on CRLF-powered desync attacks warned that header injection can do far more than trigger open redirects or XSS, enabling attackers to "behead" HTTP streams and create severe front-end/back-end parsing mismatches. Related research on ambiguous chunk line terminators and chunk-extension parsing has shown how subtle differences in HTTP/1.1 handling can be turned into cache poisoning, security-control bypass, unauthorized access, and denial-of-service conditions.
Red Hat documented multiple affected implementations under CWE-444. CVE-2026-33870 in Netty was rated Important and stems from incorrect parsing of quoted strings in HTTP/1.1 chunked transfer-encoding extension values, with no acceptable mitigation listed beyond product fixes. CVE-2024-52304 in aiohttp affects deployments using the pure Python parser, where newline handling in chunk extensions can let attackers bypass proxies or firewalls. CVE-2026-1525 in Undici allows duplicate Content-Length headers through case-variant names, creating malformed requests that can trigger request smuggling or DoS. Supporting tooling such as smugchunks has emerged to detect chunk-parsing discrepancies in black-box testing, underscoring that these desync issues are practical and span multiple widely used HTTP stacks.

See affected versions and whether adversaries are exploiting it.
12 events from the most recent confirmed update back to the earliest known activity.
Libevent committed changes to its HTTP subsystem that reject conflicting Transfer-Encoding and Content-Length headers, detect duplicate Content-Length headers, and fail malformed requests with an invalid-header error to prevent request smuggling. The patch also added regression tests covering chunked parsing and Transfer-Encoding validation behavior.
Red Hat listed additional fixes for CVE-2026-33870 in May, including AMQ Broker 7.12.7 and 7.13.5, Apache Camel 4.18.1 for Spring Boot, and Cryostat 4 on RHEL 9.
On April 14 and April 16, Red Hat listed fixes for CVE-2026-33870 in products including Red Hat builds of Quarkus, Apache Camel for Quarkus, and AMQ Broker 7.14.0.
Red Hat published a public vulnerability record for CVE-2026-33870, describing an Important-severity Netty request smuggling flaw caused by incorrect parsing of quoted strings in HTTP/1.1 chunked transfer encoding extension values.
Red Hat made its vulnerability record for CVE-2024-52304 public, documenting an aiohttp request smuggling flaw caused by incorrect parsing of newlines in HTTP chunk extensions.
A Reddit user, t0xodile, posted the PortSwigger paper on r/netsec, amplifying research on CRLF-powered HTTP stream desynchronization attacks.
A PortSwigger paper titled "CRLF-Powered Desync Attacks: Beheading HTTP Streams" described how HTTP header injection via CRLF can enable severe HTTP desynchronization attacks.
Red Hat last modified its CVE-2026-33870 record, updating the public vulnerability entry for the Netty request smuggling issue.
Red Hat Bugzilla documented CVE-2026-1527 in Undici, where attacker-controlled input in the upgrade option of client.request() can inject CRLF sequences, enabling arbitrary HTTP header injection, premature request termination, and possible smuggling to non-HTTP services such as Redis, Memcached, and Elasticsearch. Red Hat said fixes were available for RHEL 8, 9, and 10 through RHSA-2026:7670, RHSA-2026:7350, and RHSA-2026:7675.
Red Hat reported that the Undici issue had been addressed through multiple RHSA advisories affecting RHEL 8, 9, 10, extended update support streams, and Cryostat 4 on RHEL 9.
A Red Hat Bugzilla entry documented CVE-2026-1525 in Undici, where case-variant duplicate Content-Length headers can produce malformed HTTP/1.1 requests leading to denial of service or request smuggling.
Red Hat issued multiple RHSA advisories in late 2024 and early 2025 to fix CVE-2024-52304 across affected Ansible Automation Platform components, including automation-controller, python3.11-aiohttp, and lightspeed-related packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
12 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcereddit.com
Open sourcegithub.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcegithub.com
Open sourcew4ke.info
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.