HTTP/3 connection contamination: an upcoming threat?
portswigger.net | research | #web-security | #http2 | #reverse-proxy | #http3 | #connection-coalescing | #first-request-routing
Summary
First-request routing plus browser connection coalescing enables HTTP connection contamination: XSS on one hostname can compromise another sharing the connection — a threat set to grow with HTTP/3.
- Published
- Collected
Skip to content