AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
ResearchApache Traffic ServerOur summary
A new AI-assisted research system called HTTP Terminator, developed by James Kettle at PortSwigger, has uncovered innovative HTTP desynchronization techniques following an analysis of 30,000 possible vectors. During this process, a related manual investigation also revealed a previously unknown zero-day flaw in Apache Traffic Server, tracked as CVE-2026-63078. The vulnerability, which affects how the server processes requests, has now been patched but lacks clear documentation linking it to a specific version in official records. The research highlights the potential of AI in identifying complex web security issues, including new desync methods like 'dangling-byte' that improve the reliability of response queue poisoning attacks.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.