vulns.co
/
GKData.io MCP

Back to Bypasses

Request body parsing differences

Compare how the edge and application handle a documented request when its body is valid, malformed, duplicated, or sent with an alternate supported media type. Use only harmless fields and owned records.

Tags: http, parsing, api, authorized-testing

Techniques

Content type agreement

Check whether a route consistently rejects a body whose declared type does not match its syntax; inconsistencies can expose validation gaps.

  • Content-Type: application/json with a minimal valid JSON test body
  • Content-Type: application/x-www-form-urlencoded with the same benign field

Duplicate field policy

Use distinct non-sensitive markers to learn whether the parser accepts first, last, arrays, or rejects duplicates.

  • role_hint=CANARY-A&role_hint=CANARY-B
  • {"note":"CANARY-A","note":"CANARY-B"}

Boundary behavior

For upload or multipart endpoints, compare ordinary form fields and an empty, permitted file field; do not submit oversized data or unsafe file content.

  • multipart/form-data with a small text field
  • empty optional file field with a benign .txt fixture