reddit hackernews mail facebook facebook linkedin
h2cSmuggler

h2cSmuggler

HTTP Request Smuggling over HTTP/2 Cleartext.

h2cSmuggler smuggles HTTP traffic past insecure edge-server proxy_pass configurations by establishing HTTP/2 cleartext (h2c) communications with h2c-compatible back-end servers, allowing a bypass of proxy rules and access controls.