TL;DR: Recent Portswigger research introduced novel HTTP desync techniques discovered through an AI-assisted research system called the HTTP Terminator. Some implementations reuse parsing logic for both HTTP requests and HTTP responses. On-Prem WAF customers should enable dedicated available controls such as Response Forking – HTTP Desync policy (if not enabled) to mitigate these attacks. Imperva Cloud WAF and WAF Gateway customers are protected against the practical desync techniques described in the research. The post Imperva Customers Protected Against Novel HTTP Desync Attacks appeared first on Blog.