
HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)
CybersecurityVulnerabilitiesNetworkProtocolsAIinSecurity
The post describes a security researcher’s investigation into a request smuggling vulnerability in HAProxy, specifically involving HTTP/3 to HTTP/1 desynchronization via a standalone QUIC FIN. The researcher credits inspiration from u/albinowax’s work on request smuggling and mentions prior experience in web security, including SQLi, XSS, and access control flaws. The discovery resulted from deeper exploration into networking protocols and HAProxy’s code implementation. The post also notes the use of AI in the research process.