WhisperX tag archive

#http-request-smuggling

This page collects WhisperX intelligence signals tagged #http-request-smuggling. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-22 14:27:38 · GitHub Issues

1. Axios CRLF Header Injection Chains with Prototype Pollution to Enable AWS Credential Theft via IMDSv2 Bypass — CVSS 9.9

A critical CRLF injection flaw in the Axios HTTP client library, tracked as CVE-2026-40175, allows attackers to inject arbitrary headers into outbound HTTP requests when combined with prototype pollution vulnerabilities present in other JavaScript dependencies. Security researchers at Heimdall Security flagged the issu...