PortSwigger AI Finds New Desync Paths

PortSwigger's James Kettle said at Black Hat USA 2026 that his open-source tool, HTTP Terminator, autonomously invented novel HTTP request-smuggling, or desync, techniques and used them against real enterprise sites, including several financial services companies. The tool was built to see whether AI could move past finding known bugs and start creating new attack techniques on its own. The core trick is parsing mismatch: the tool keeps trying odd request shapes until the front end and back end disagree about where one request ends and the next begins, which can let hidden content slip past the first layer as if it were harmless. That matters because the working exploit may not match the small set of payloads defenders already test for. For teams running sites behind reverse proxies, CDNs, or load balancers, the exposure is in the whole request chain, not one named product. If front-end and back-end parsing diverge, automated tools can now hunt for a usable path at scale even when familiar request-smuggling checks come up clean.

Part of the PlainSec briefing for 2026-08-27

Every edition of this story: PortSwigger AI Finds New Desync Paths

Sources