logo

What the 13% Looks Like: A Case Study

ID: 2b4d9589-0128-5b2d-bfd9-6942419afd5e

STIX ID: report--2b4d9589-0128-5b2d-bfd9-6942419afd5e

Feed Name: NCC Research

Threat Score
80/100

Date Published: 2026-07-24

Date Updated: 2026-08-04

...
...

This piece analyzes James Kettle's 2025 research “HTTP/1.1 Must Die,” which introduced novel HTTP request smuggling/desynchronisation techniques (eg. Expect-header desync, 0.CL inversion, chunk-extension and browser-driven desync) that led to CVE-2025-32094 and CVE-2025-49005, produced substantial bounties, and enabled cache-poisoning at scale affecting roughly 24 million websites; it uses that case to argue AI tools reliably find documented issues but cannot discover frontier, unmapped techniques that require deep human systems expertise, and recommends funding human research alongside AI tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.