home tags events about rss login

Things happen.

horia bonked 08 Jun 2026 10:10 -0700
original: ethicalhacker@infosec.exchange

New disclosure: CL.TE HTTP request smuggling in OpenBSD relayd.
Latent in relay_http.c since 2012 (OpenBSD 5.2). The body was parsed as chunked but a co-present Content-Length header wasn't stripped before forwarding to backend, contrary to RFC 9112 §6.1.
Found by a targeted source-review pass against the RFC framing rules. Fixed in -current 2026-06-03 in a single commit.
https://stuart-thomas.com/research/relayd-cl-te-smuggling/
#infosec #OpenBSD #vulndisclosure

horia honked 03 Jun 2026 10:48 -0700

If you don't love my syspatch, you don't deserve my uptime