New HTTP/1.1 Desync Attacks Threaten 34% of the Web Starting Wednesday
By
Bender
Slow-proofed and worth the wait. Worth its weight in flour.
Summary
The article discusses an impending security threat to HTTP/1.1, a protocol still used by about 34% of the web. On August 6, researcher James Kettle will reveal new classes of desync attacks that compromise multiple CDNs, potentially leading to widespread disruptions. The piece highlights the ongoing vulnerability of HTTP/1.1 to request smuggling attacks, a problem first identified six years ago.
Key quotes
· 4 pulledUpstream HTTP/1.1 is inherently insecure and consistently exposes millions of websites to hostile takeover.
Six years after we exposed the threat of HTTP desync attacks, there’s still no end in sight.
James Kettle from PortSwigger Research will reveal new classes of desync attack that enabled him to compromise multiple CDNs and kick off the desync endgame.
About 34% of the web is still powered by HTTP/1.1 and that protocol will likely come under severe attack starting on Wednesday.
You might also wanna read
GitHub Bans Security Researcher Over Windows Zero-Day Exploit Code in YellowKey Dispute
Security researcher Nightmare-Eclipse reportedly lost his GitHub account after posting Windows zero-day exploit code related to the YellowKe
Suspicious hidden message discovered in jqwik testing library 1.10.0
A developer reports discovering a suspicious string in the jqwik testing library (version 1.10.0) that appears during Maven test runs. The s
Attackers exploit FortiClient EMS vulnerability (CVE-2026-35616) to deliver infostealer to enterprise devices
Attackers are exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver a broad-spectru
Critical Gogs RCE bug (CVSS 9.4) remains unpatched; exploit module now public
A critical remote code execution (RCE) vulnerability rated 9.4/10 has been discovered in Gogs, a popular open-source self-hosted Git service
GrapheneOS: A privacy-focused, open-source mobile OS with Android app compatibility
GrapheneOS is a non-profit, open-source mobile operating system focused on privacy and security, with full Android app compatibility. Founde
Anthropic Releases Free Security Plugin for Claude Code Terminal to Detect Vulnerabilities
Anthropic has released a free security-guidance plugin for its Claude Code terminal tool that autonomously reviews code edits, model outputs
cybersecuritynews.com·11h ago