Skip to content

AI System “HTTP Terminator” Discovers New HTTP Desync Techniques and Zero-Day in Apache Traffic Server

Bottom line: An AI-powered research system generated new HTTP desync techniques after evaluating 30,000 attack candidates, indirectly contributing to the discovery of an Apache Traffic Server zero-day.

PortSwigger, using the AI-powered research system HTTP Terminator developed by James Kettle, identified and practically demonstrated new variants of HTTP desynchronization attacks. A separate, human-driven investigation process additionally uncovered a zero-day vulnerability in Apache Traffic Server.

PortSwigger reports that the system HTTP Terminator, developed by James Kettle, generated and verified new techniques for HTTP request desynchronization (HTTP desync). In the process, the system searched through around 30,000 candidates for possible attack vectors and tested these against an equal number of websites as part of the scanning process. This automated exploration produced new variants of desync attacks that had not previously been known.

In parallel to this AI-assisted approach, a human-led, cascading investigation led to the discovery of a zero-day vulnerability in Apache Traffic Server. HTTP desync attacks aim to exploit discrepancies in the interpretation of HTTP requests between upstream proxies, load balancers, and backend servers in order to shift request boundaries, bypass security controls, or manipulate other users’ requests.

For CISOs and security teams, it is relevant that HTTP desync vulnerabilities can occur in multi-tier web infrastructures with reverse proxies, CDNs, or load balancers, and can have significant impact there, such as request smuggling, cache poisoning, or bypassing authentication mechanisms. Since the discovery resulted from an automated, AI-powered process that tested real-world websites at scale, the case shows that such techniques can increasingly be identified systematically and at scale — including by attackers.

Specific technical details on the new desync techniques, as well as on the Apache Traffic Server vulnerability, including a possible CVE identifier or patch status, were not provided in the source at hand. Organizations affected that use Apache Traffic Server should monitor announcements from PortSwigger and Apache regarding official advisories and patches.


Source: thehackernews.com · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: