AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger's James Kettle released HTTP Terminator, an AI-assisted research system that generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. The tool tested 30,000 websites and found roughly 700 vulnerable targets including banks, government infrastructure, security products, and an airport. A separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server.
Overview
| Attribute | Detail |
|---|---|
| Researcher | James Kettle (PortSwigger) |
| Tool | HTTP Terminator (AI-assisted) |
| Date | 2026-08-07 |
| Source | The Hacker News |
Research Findings
- 30,000 candidate desync vectors explored by AI
- ~700 vulnerable targets including banks, government infrastructure, security products, and an airport
- Apache Traffic Server zero-day discovered via human-guided cascade
- New desync triggers identified
- Dual-matching Content-Length pattern discovered
- "Dangling-byte" technique for more reliable response queue poisoning (RQP)
Significance
This research demonstrates the power of AI-assisted vulnerability discovery at scale, and underscores the ongoing prevalence of HTTP desync vulnerabilities across critical infrastructure and enterprise web applications. The Apache Traffic Server zero-day is particularly notable given its widespread use in CDN and caching infrastructure.
Related Pages
- New Css Attacks Can Break Webmail Defenses To Steal Passwords And Tokens โ PortSwigger's other major web security research this week (Black Hat 2026)