request-smuggling

Detect and exploit HTTP request smuggling across front-end and back-end servers.

1|1|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/erkanrzgc/cyberm4fia-scanner --skill request-smuggling-erkanrzgc
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: request-smuggling
Source: https://github.com/erkanrzgc/cyberm4fia-scanner/tree/main/core/ai_skills/offensive-request-smuggling
Command: npx skills add https://github.com/erkanrzgc/cyberm4fia-scanner --skill request-smuggling-erkanrzgc

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

HTTP request smuggling vulnerabilities allow desynchronization between front-end and back-end servers, enabling security bypasses, data leakage, and potential control over downstream services.

Core Features & Use Cases

  • Detect CL.TE, TE.CL, TE.TE, and HTTP/2 desync scenarios across proxies, load balancers, and edge servers.
  • Provide a structured methodology for detection, confirmation, and exploitation with safety measures and remediation guidance.
  • Applicable to web applications, APIs, gateways, and cloud edge configurations in modern architectures.

Quick Start

Analyze a target edge proxy to identify and validate request smuggling weaknesses and gather actionable remediation steps.

Frequently Asked Questions about request-smuggling

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I test for HTTP request smuggling across edge proxies?▼

To test for HTTP request smuggling across edge proxies, apply a structured methodology covering detection, confirmation, and exploitation to identify desynchronization vulnerabilities between front-end and back-end servers.

What is HTTP request smuggling and how does it affect web applications?▼

HTTP request smuggling is a desynchronization vulnerability between front-end and back-end servers that enables security bypasses, data leakage, and potential control over downstream services in web applications and APIs.

Can I detect HTTP/2 downgrade request smuggling with this methodology?▼

Yes, you can detect HTTP/2 downgrade desync scenarios, alongside CL.TE, TE.CL, and TE.TE vulnerabilities, across proxies, load balancers, CDNs, and gateways in modern cloud edge configurations.

How do I exploit CL.TE and TE.CL vulnerabilities in load balancers?▼

Exploit CL.TE and TE.CL vulnerabilities in load balancers by following structured detection and confirmation steps with safety checks, targeting desynchronization between edge servers and back-end infrastructure.

Does this request smuggling testing approach provide remediation guidance?▼

Yes, the approach provides actionable remediation guidance alongside safety checks, ensuring you can validate request smuggling weaknesses across network infrastructure and gather steps to fix the identified desynchronization issues.