AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
AI Generated Image

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

The Hacker News technology

Key Points:

  • PortSwigger's AI-assisted system, HTTP Terminator, autonomously generated and proved new HTTP desynchronization techniques after analyzing 30,000 candidate vectors, identifying roughly 700 vulnerable targets across banks, government infrastructure, and security products.
  • The research introduced new desync triggers, including a dual-matching Content-Length pattern and a "dangling-byte" technique to improve response queue poisoning (RQP) reliability, which can expose sensitive user data like session cookies or API keys.
  • A human-guided cascade discovered a zero-day vulnerability in Apache Traffic Server (CVE-2026-63078), which has been patched, although public records for this CVE are not yet available, creating a verification gap for defenders.
  • Shared-Parser Confusion, a broader attack concept where response-processing rules may be misapplied due to reused parsing logic, was proposed by HTTP Terminator and validated by PortSwigger's James Kettle, highlighting a novel vulnerability class.
  • PortSwigger has open-sourced HTTP Terminator, which uses Claude models for document extraction and test-case generation, and separate researchers have released tools for CRLF-powered desync attacks; additionally, GPT-5.6 Sol showed a 30% success rate in rediscovery benchmarks with inspiration techniques.

Trending Business

Trending Technology

Trending Health