PortSwigger research warns that ambiguous HTTP/1.1 request boundaries continue to enable HTTP request-smuggling, or desynchronization, attacks across tens of millions of websites. The research introduced new desynchronization classes, reported critical exposure in major CDN infrastructure, and has been associated with compromises of three major CDNs and more than $350,000 in bug-bounty awards despite years of mitigations.
One variant, 0.CL, arises when a front end and back end disagree over a malformed or zero Content-Length header: the front end may forward a request without a body while the back end waits for one. Attackers can exploit an early-response endpoint to cause the back end to consume bytes from a following request, enabling queue poisoning and potentially cross-site scripting against another user. Organizations should eliminate HTTP/1.1 from proxy-to-origin paths where feasible by deploying HTTP/2 or later end to end, and continuously test any remaining HTTP/1.1 intermediaries for parser discrepancies.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A video published by John Hammond featured a discussion with James Kettle about the HTTP/1.1 Must Die research, including the risk posed by HTTP/1.1 request-boundary ambiguity and upstream HTTP/1.1 connections.
HTTP request smuggling was first publicly discovered approximately 21 years before September 2025, establishing the underlying vulnerability class later described as HTTP desynchronization.
A PortSwigger walkthrough demonstrated detecting a 0.CL parser discrepancy using a malformed Content-Length header and converting a confirmed condition into CL.0 queue poisoning. The lab examples showed attacker-controlled responses and victim-side XSS through desynchronized back-end request handling.
James Kettle and collaborating researchers released “HTTP/1.1 Must Die: The Desync Endgame,” introducing two new HTTP desynchronization classes. The research reportedly compromised three major CDNs, exposed critical issues affecting tens of millions of websites, and generated more than $350,000 in bug-bounty payouts.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
portswigger.net
Open sourceportswigger.net
Open sourceportswigger.net
Open sourceportswigger.net
Open sourcehttp1mustdie.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.