drogonframework / drogonframework/drogon

Http 1.1 susceptible to http request smuggler

Open
#2,426 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
C++
Stars
14.3k
Forks
1.4k
Avg merge
1d 12h
Merged PRs (30d)
15

Description

Hello,

I saw the following presentation at Defcon: https://http1mustdie.com and was wondering if Drogon is vulnerable.

Please advise,

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the linked DEF CON presentation and Drogon's HTTP/1.1 request parsing and connection-handling entry points. Determine whether the reported request-smuggling conditions apply to Drogon, then document the affected behavior and any required remediation or tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
networking, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.