- PortSwigger’s AI system, HTTP Terminator, autonomously generated and validated novel HTTP desynchronization attacks after exploring 30,000 candidate vectors.
- The research identified roughly 700 vulnerable targets across banks, government infrastructure, and an airport, including a confirmed technique affecting a U.S. bank.
- Human-guided analysis exposed a zero-day in Apache Traffic Server, tracked as CVE-2026-63078, which has reportedly been patched.
- A new “dangling-byte” technique improves response queue poisoning (RQP) reliability, potentially exposing session cookies or API keys.
PortSwigger revealed that its AI-assisted research system, HTTP Terminator, autonomously generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate vectors. The system, built by James Kettle, tested 30,000 websites and found roughly 700 vulnerable targets, including banks, government infrastructure, security products, and an airport.
Consequently, the research produced new desync triggers, a dual-matching Content-Length pattern, and a “dangling-byte” technique to make response queue poisoning (RQP) more reliable. RQP can potentially make a front end lose track of which back-end response belongs to which user, exposing session cookies or API keys.
One Content-Type: multipart/byteranges technique worked across multiple server implementations and exposed more than 200 websites in the test set, including an unnamed U.S. bank. In the human-guided cascade, a malformed request exposed a desynchronization zero-day in Apache Traffic Server, tracked as CVE-2026-63078, which the researchers said has been patched.
The system also proposed Shared-Parser Confusion, a broader attack concept that Kettle later validated. “Neither of us would have discovered it alone,” he said, defining the autonomy boundary where the system generated and proved techniques without direct human discovery input.
PortSwigger has open-sourced HTTP Terminator, which uses Claude for document extraction and test-case generation. Kettle separately tested newer models on a rediscovery benchmark and reported a 30% success rate for GPT-5.6 Sol when given an inspiration technique.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
