vulns.co
/
GKData.io MCP

PortSwigger · 1 min read

Upstream HTTP framing and parser-consistency boundaries

The researcher explains how inconsistent message-boundary interpretation across proxies and origins can break request isolation on shared upstream connections. Client-facing HTTP/2 alone does not remove this risk when intermediaries translate requests into HTTP/1.1.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Review framing contracts across every intermediary, including protocol translation and connection reuse. Consider upstream HTTP/2, consistent validation and normalization, and isolation tradeoffs where legacy transport remains. Assess remediation against the architecture rather than relying on a front-end protocol label or filtering claim.

Before reading

  • HTTP request and response semantics
  • Reverse-proxy and origin-server architecture

Context and limits

  • Protocol migration is the researcher’s recommendation, not proof that every HTTP/2 implementation is secure.
  • Historical cases and vendor support observations do not establish current vulnerabilities or feature availability.
  • Linked operational material is omitted. No individual award qualification or testing authorization is implied.

Sources and provenance

  1. HTTP/1.1 must die: the desync endgame PortSwigger · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software