topic
Verified 2026-09-18

HTTP Request Smuggling and Message Framing

Request smuggling exploits disagreement between intermediaries about where an HTTP message ends.

Normalize and reject ambiguous framing, follow the HTTP version’s parsing rules, remove hop-by-hop fields at proxy boundaries, and keep front-end and back-end parsers aligned.

httpsecurityproxyframing

Reference (http)

Content-Length: 4
Transfer-Encoding: chunked

Normalize and reject ambiguous framing, follow the HTTP version’s parsing rules, remove hop-by-hop fields at proxy boundaries, and keep front-end and back-end parsers aligned.

Common mistakes

  • Accepting conflicting Content-Length and Transfer-Encoding values or forwarding them unchanged.
Permalink: https://merginit.com/reference/http/request-smuggling