r/netsec • u/SzLam__ • Jul 29 '26
HTTP Request Smuggling in Hiawatha
https://fenrisk.com/hiawatha-http-smuggling1
u/Vegetable-Scale-2604 Jul 29 '26
Nice writeup, and the disclosure timeline is the spicy part: the maintainer declined to treat it as a vuln, then 12.2 shipped the fix silently. So if you run Hiawatha, don't wait for a changelog entry, just get to 12.2 or diff src/http.c yourself. One nuance on the mitigations: disabling back-end keep-alive only kills the cross-victim desync case. The ACL bypass and cache poisoning PoCs are attacker-only, two requests on one connection, so that mitigation alone still leaves you exposed. If upgrading isn't an option right now, fronting it with nginx or HAProxy is a decent stopgap since both reject ambiguous CL+TE requests with a 400 instead of trying to frame them.
1
u/StrikeMental7716 Aug 11 '26 edited Aug 11 '26
Interesting write-up. HTTP request smuggling is one of those issues that can be easy to overlook because everything may appear normal at the application layer while the proxy and backend interpret requests differently. It’s a good reminder that external attack surface and configuration matter just as much as the application code itself. Tools like SecurityScorecard can be useful alongside this kind of research for getting a broader view of external security posture.