logo

me vs request smugglingPOST

ID: 354d480f-3595-5f70-972b-6d326c44fb04

STIX ID: report--354d480f-3595-5f70-972b-6d326c44fb04

Feed Name: SensePost Blog

Threat Score
55/100

Date Published: 2022-07-19

Date Updated: 2026-04-30

...
...

This blog post documents exploiting an HTTP/2-to-HTTP/1.1 request smuggling flaw in Varnish (CVE-2021-36740) within a CTF environment, details the debugging and differences across backends (nginx, netcat, Apache), and shows how the smuggle was chained with a Twig template injection (CVE-2022-23614) to bypass an ACL and execute a command to retrieve a flag.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.