facebook / proxygen

A collection of C++ HTTP libraries including an easy to use HTTP server.
Other
8.16k stars 1.5k forks source link

Request smuggling vulnerability in Proxygen #486

Open kenballus opened 9 months ago

kenballus commented 9 months ago

I found a bug in Proxygen's HTTP parser that is usable to execute request smuggling attacks against Proxygen-based web services when they are running behind any of the following HTTP intermediary servers:

Unfortunately, I can't report this vulnerability without a Facebook account, which I don't have. Could someone from the Proxygen team please get in touch with me using email? My email address is at the bottom of my webpage.

Thanks!