CVE Tools

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

The Hacker NewsBy The Hacker News

ResearchApache Traffic Server

Our summary

A new AI-assisted research system called HTTP Terminator, developed by James Kettle at PortSwigger, has uncovered innovative HTTP desynchronization techniques following an analysis of 30,000 possible vectors. During this process, a related manual investigation also revealed a previously unknown zero-day flaw in Apache Traffic Server, tracked as CVE-2026-63078. The vulnerability, which affects how the server processes requests, has now been patched but lacks clear documentation linking it to a specific version in official records. The research highlights the potential of AI in identifying complex web security issues, including new desync methods like 'dangling-byte' that improve the reliability of response queue poisoning attacks.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store