request-smuggling

Detect and exploit HTTP request smuggling across front-end and back-end servers.

1|1|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/erkanrzgc/cyberm4fia-scanner --skill request-smuggling-erkanrzgc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: request-smuggling
Source: https://github.com/erkanrzgc/cyberm4fia-scanner/tree/main/core/ai_skills/offensive-request-smuggling
Command: npx skills add https://github.com/erkanrzgc/cyberm4fia-scanner --skill request-smuggling-erkanrzgc

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

HTTP request smuggling vulnerabilities allow desynchronization between front-end and back-end servers, enabling security bypasses, data leakage, and potential control over downstream services.

Core Features & Use Cases

  • Detect CL.TE, TE.CL, TE.TE, and HTTP/2 desync scenarios across proxies, load balancers, and edge servers.
  • Provide a structured methodology for detection, confirmation, and exploitation with safety measures and remediation guidance.
  • Applicable to web applications, APIs, gateways, and cloud edge configurations in modern architectures.

Quick Start

Analyze a target edge proxy to identify and validate request smuggling weaknesses and gather actionable remediation steps.

Frequently Asked Questions about request-smuggling

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I test for HTTP request smuggling across edge proxies?

To test for HTTP request smuggling across edge proxies, apply a structured methodology covering detection, confirmation, and exploitation to identify desynchronization vulnerabilities between front-end and back-end servers.

What is HTTP request smuggling and how does it affect web applications?

HTTP request smuggling is a desynchronization vulnerability between front-end and back-end servers that enables security bypasses, data leakage, and potential control over downstream services in web applications and APIs.

Can I detect HTTP/2 downgrade request smuggling with this methodology?

Yes, you can detect HTTP/2 downgrade desync scenarios, alongside CL.TE, TE.CL, and TE.TE vulnerabilities, across proxies, load balancers, CDNs, and gateways in modern cloud edge configurations.

How do I exploit CL.TE and TE.CL vulnerabilities in load balancers?

Exploit CL.TE and TE.CL vulnerabilities in load balancers by following structured detection and confirmation steps with safety checks, targeting desynchronization between edge servers and back-end infrastructure.

Does this request smuggling testing approach provide remediation guidance?

Yes, the approach provides actionable remediation guidance alongside safety checks, ensuring you can validate request smuggling weaknesses across network infrastructure and gather steps to fix the identified desynchronization issues.