NullRabbit
cohort.v1
Research · Tag · Request Smuggling

Posts tagged request smuggling.

1 entry · sorted: recency← All research
CLOUDFLARE
2026-06-26

We slipped a path past Cloudflare's edge. The fix is one checkbox.

Cloudflare resolves dot-segments in a URL only far enough to reject the obvious escapes, then forwards the raw, still-encoded path to your origin, which quietly resolves it the rest of the way. Your edge rules see one path; your server serves another. Cloudflare even warns you about it, in a banner most people scroll past.

Simon Morley
Read →5 min read