Topic · 2 articles
request smuggling
Advanced level
2Premium
HTTP request smuggling — H2→H1 desync, TE.CL, CL.TE and H2.CL in 2026
An updated catalog of HTTP smuggling: classic CL.TE, TE.CL, H2→H1 downgrade desyncs, HTTP/2 SETTINGS frame abuse, chunked extensions and HTTP/2 pseudo-headers.
16 minhttp-smugglingdesynchttp2
Read article
With account
HTTP Request Smuggling — CL.TE, TE.CL, TE.TE and caching exploitation
When the frontend and the backend interpret the same request differently. Smuggling for auth bypass, cache poisoning, victim-aware attacks.
14 minhttp-smugglingrequest-smugglingcache-poisoning
Read article
Practice request smuggling with real labs
Apply the techniques in safe environments based on real bug bounty reports.
- hunters training
- 711
- labs from real reports
- 55
- completions
- 1,205
- in bounties practiced
- $213,970
hunters training
labs from real reports
completions
in bounties practiced
46 flags captured this week·Real reports from HackerOne · Bugcrowd · Intigriti·No commitment·Free Academy
BBLabs · bug bounty training
Stop reading about bugs and start hunting them
Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.
No card · free Academy · cancel anytime