HomeSecurityApache: AI-Assisted HTTP Terminator Discovers New HTTP Desynchronization Techniques

Apache: AI-Assisted HTTP Terminator Discovers New HTTP Desynchronization Techniques

PortSwigger reports that HTTP Terminator, an artificial intelligence (AI)-assisted research system created by James Kettle, created and demonstrated new HTTP desynchronization techniques after exploring 30,000 candidate attack paths.

See also: HTTP/2 Bomb: DoS vulnerability in NGINX, Apache, IIS and Cloudflare

Article Image: AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger reported that a separate human-driven discovery also uncovered a zero-day in Apache Traffic Server. Kettle reported that HTTP Terminator tested 30,000 websites where scanning was authorized through bug bounty or vulnerability disclosure programs and found about 700 vulnerable targets before deeper validation and response queue poisoning (RQP) research.

Kettle noted that these findings involved banks, government infrastructure, security products and an airport.

The research produced new desynchronization triggers, a double Content-Length matching pattern, and a “dangling-byte” technique designed to make RQP more reliable. RQP can potentially cause the front end to lose track of which back-end response belongs to which user, potentially exposing another user’s response, including session cookies or API keys.

The researchers also uncovered Shared-Parser Confusion, a broader attack concept that the system suggested but Kettle validated. The defense has not changed: PortSwigger recommends avoiding HTTP/1.1 upstream. Where HTTP/1.1 cannot be removed, whitelisting methods at both levels and restricting the methods that can carry request bodies is recommended.

In the white paper, Kettle explained that he fed HTTP Terminator 138 HTTP and SMTP RFCs. These RFCs were broken down into about 15,000 small pieces and used as inspiration to generate 30,000 unique candidate routes.

A Content-Type: multipart/byteranges technique worked on multiple server implementations and exposed more than 200 websites in the test set, including an anonymous U.S. bank.

The independent research then tested 16 ideas for improving RQP. Only the dangling-byte technique survived the evaluation. It leaves a hidden request one byte short, so that the back-end's second response is not produced until the victim provides the missing byte, eliminating a race condition that otherwise makes RQP unreliable on many websites.

See also: Critical flaw in Apache HTTP/2 allows DoS and RCE

HTTP Terminator - SecNews.gr

In the human-driven discovery, a malformed request ultimately exposed the desynchronization zero-day in Apache Traffic Server. The researchers said the issue has now been patched and is being tracked as CVE-2026-63078.

An August 7 check by The Hacker News found no public listing for CVE-2026-63078 on CVE.org or NVD, and Apache's July advisory covering 34 vulnerabilities did not mention it. This leaves a verification gap around Apache's case: the public listings cited do not yet allow defenders to map CVE-2026-63078 to a specific version of Traffic Server that has been patched.

Kettle explained that Shared-Parser Confusion arose when HTTP Terminator noticed that response processing rules could be incorrectly applied to requests when servers reused parsing logic. The system suggested the concept, but Kettle, director of research at PortSwigger, validated and generalized it. “None of us would have discovered this on our own,” he said.

This distinction defines the limit of autonomy in this research: the system created and demonstrated several techniques autonomously, while the Apache zero-day and Shared-Parser Confusion still required Kettle's intervention.

PortSwigger has open-sourced the HTTP Terminator. The document does not specify which model or version each autonomous discovery created. The published implementation uses Claude to extract documents and create test cases, while the researcher stage requires Claude Code.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The researchers behind CRLF desync attacks have also publicly released tools for studying this class of attacks, including crlf-desyncs and crlf-powered-desync-scanner.

See also: Oracle WebLogic CPU July 2026: 5 critical RCEs — deserialization in T3/IIOP/HTTP/SOAP

Article image: Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Kettle tested separate newer models on a rediscovery benchmark and reported a 30% success rate for GPT-5.6 Sol when given an inspiration technique.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS