<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Protocol Security on Nalar</title>
    <link>https://nalar.dev/tags/protocol-security/</link>
    <description>Recent content in Protocol Security on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 17 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/protocol-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>HTTP Request Smuggling Begins at a Message-Framing Disagreement</title>
      <link>https://nalar.dev/http-request-smuggling-begins-at-a-message-framing-disagreement/</link>
      <pubDate>Thu, 17 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://nalar.dev/http-request-smuggling-begins-at-a-message-framing-disagreement/</guid>
      <description>&lt;h1 id=&#34;http-request-smuggling-begins-at-a-message-framing-disagreement&#34;&gt;HTTP Request Smuggling Begins at a Message-Framing Disagreement&lt;/h1&gt;&#xA;&lt;p&gt;A reverse proxy can validate an HTTP request, route it to an approved application, and still deliver a different request sequence from the one it believed it accepted. The failure does not require the proxy to ignore authentication or the origin to execute malformed syntax. It can arise when the two HTTP processors disagree about the byte at which one request ends and the next begins.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
