HTTP Multiline headers

Опубликовано: 12 Апрель 2026
на канале: Bug Bounty Reports Explained
1,960
86

Full video:    • Request smuggling - do more than running t...  
📕 The full case study: https://members.bugbountyexplained.co...
📧 Subscribe to BBRE Premium: https://bbre.dev/premium
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw

Request smuggling is an amazing bug class! But I barely ever did more than running Request Smuggler. So I've analysed tens of reports and in this video, I'll break down the most common root causes and I'll give you some ideas for future research.

🖥 Get $100 in credits for Digital Ocean: https://bbre.dev/do

Reports mentioned in the full video:

Reports mentioned in the video:
Whitespace characters in CL/TE headers
https://hackerone.com/reports/1501679
https://hackerone.com/reports/1630667
Incorrect prioritization of CL/TE
https://hackerone.com/reports/488147
Multiple TE/CL headers
https://hackerone.com/reports/867577
Ignoring the TE/CL headers
https://blog.jeti.pw/posts/knocking-o...
Not closing the connection
https://regilero.github.io/english/se...
HTTP/2 downgrade forwarding CL/TE
https://portswigger.net/research/http2
Only \n or \r as a newline
https://hackerone.com/reports/2032842
Not a literal "chunked" TE
https://hackerone.com/reports/1594627
   • The hardest CTF task I’ve ever done!  
CRLF injection
https://portswigger.net/research/maki...
https://members.bugbountyexplained.co...
Trailer parsing
https://hackerone.com/reports/2280391
H2C upgrade
https://www.assetnote.io/resources/re...
Converting \r to -
https://hackerone.com/reports/922597
Chunk extensions
https://hackerone.com/reports/1238099