CAPEC 33 HTTP Request Smuggling

Stable Detailed Medium Risk
Severity High

Description

{'xhtml:p': ['An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages using various HTTP headers, request-line and body parameters as well as message sizes (denoted by the end of message signaled by a given HTTP header) by different intermediary HTTP agents (e.g., load balancer, reverse proxy, web caching proxies, application firewalls, etc.) to secretly send unauthorized and malicious HTTP requests to a back-end HTTP agent (e.g., web server).', 'See CanPrecede relationships for possible consequences.']}

Attack Execution Flow

4

Mitigations

13

Consequences

Indicators

1

Relationships

Resources Required

1