drogonframework / drogonframework/drogon
Http 1.1 susceptible to http request smuggler
Open
- Dominant language
- C++
- Stars
- 14.3k
- Forks
- 1.4k
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 15
Description
Hello,
I saw the following presentation at Defcon: https://http1mustdie.com and was wondering if Drogon is vulnerable.
Please advise,
Contributor guide
Research direction
Start by reviewing the linked DEF CON presentation and Drogon's HTTP/1.1 request parsing and connection-handling entry points. Determine whether the reported request-smuggling conditions apply to Drogon, then document the affected behavior and any required remediation or tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- networking, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100