We've just published "Making desync attacks easy with TRACE" by new PortSwigger Research member Martin Doyenhard!
https://portswigger.net/research/trace-desync-attack
Making desync attacks easy with TRACE

Have you ever found an HTTP desync vulnerability that seemed impossible to exploit due to its complicated constraints? In this blogpost we will explore a new exploitation technique that can be used to

PortSwigger Research