Research · Tag · Http3
Posts tagged http3.
2 entries · sorted: recency← All research
SECURITY-RESEARCH
2026-06-24
Meet Keith, and why we're keeping it closed
We built our own HTTP engine from scratch. No normalisation, no typed header map, no helpfulness at all, because a well-behaved client quietly fixes the exact malformations you need to send. Here is what Keith is, and why we changed our minds about open-sourcing it.
Simon Morley
Read →5 min read
SECURITY-RESEARCH
2026-06-22
The h3 FIN/EOM desync, and why your smuggling tool can't send it
HTTP/3 request smuggling is almost unploughed ground. Not because the surface is small, but because nearly every tool speaks h1/h2 only, and the few that speak h3 do it through a conformant QUIC library that won't let you send the bug.
NullRabbit Labs
Read →4 min read
