NullRabbit
cohort.v1
Research · Tag · Quic

Posts tagged quic.

1 entry · sorted: recency← All research
SECURITY-RESEARCH
2026-06-22

The h3 FIN/EOM desync, and why your smuggling tool can't send it

HTTP/3 request smuggling is almost unploughed ground. Not because the surface is small, but because nearly every tool speaks h1/h2 only, and the few that speak h3 do it through a conformant QUIC library that won't let you send the bug.

NullRabbit Labs
Read →4 min read