<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Response Splitting on Red Hive</title>
		<link>https://blog.hive.red/en/tags/response-splitting/</link>
		<description>Recent content in Response Splitting on Red Hive</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
			<managingEditor>info@hive.red (Red Hive)</managingEditor>
		
		
			<webMaster>info@hive.red (Red Hive)</webMaster>
		
		
			<copyright>&lt;a href=&#34;https://creativecommons.org/licenses/by-nc/4.0/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CC BY-NC 4.0&lt;/a&gt;</copyright>
		
		
			<lastBuildDate>Fri, 14 Aug 2026 00:00:00 +0000</lastBuildDate>
		
			<atom:link href="https://blog.hive.red/en/tags/response-splitting/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Reverse Desync &#43; TE.Chunked Bypass in httpx&#43;nginx systems</title>
				<link>https://blog.hive.red/en/posts/reversedesync/</link>
				<pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate><author>info@hive.red (Red Hive)</author>
				<guid>https://blog.hive.red/en/posts/reversedesync/</guid>
				<description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;&#xA;&lt;p&gt;After reading the research by &lt;a href=&#34;https://portswigger.net/research/crlf-powered-desync-attacks&#34;&gt;Tom Stacey (@t0xodile) and Tobia Righi (@m4st3rspl1nt3r)&lt;/a&gt; on &lt;em&gt;CRLF-Powered Desync Attacks&lt;/em&gt;, I wanted to dive deeper into a specific aspect: &lt;strong&gt;Reverse Desyncs&lt;/strong&gt; (Response Splitting).&lt;/p&gt;&#xA;&lt;p&gt;I wanted to find out if they were still possible, even if just in a lab environment, what technology stack would allow it, and whether such a configuration is plausible in the wild. I empirically tested how various HTTP clients handle stacked responses and discovered that &lt;strong&gt;&lt;code&gt;httpx&lt;/code&gt;&lt;/strong&gt; (the most widely used HTTP client in Python) follows the RFC to the letter, thus lacking the &amp;ldquo;over-read&amp;rdquo; mitigation that protects browsers, &lt;code&gt;curl&lt;/code&gt;, and other libraries.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
