# HTTP/1.1 must die: Dafydd Stuttard on what this means for enterprise security

DevFeed: [HTTP/1.1 must die: Dafydd Stuttard on what this means for enterprise security](<https://devfeed.tech/articles/http-1-1-must-die-dafydd-stuttard-on-what-this-means-for-enterprise-security-7726.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/http-1-1-must-die-dafydd-stuttard-on-what-this-means-for-enterprise-security>)

Author: Andrzej Matykiewicz

Published: 2025-10-09T14:06:40Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Internet Traffic](<https://devfeed.tech/topics/internet-traffic.md>), [Microservice](<https://devfeed.tech/topics/microservice.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [http](<https://devfeed.tech/tags/http.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [internet-traffic](<https://devfeed.tech/tags/internet-traffic.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

## AI overview

The article examines why HTTP/1.1 remains a serious enterprise security risk. It discusses HTTP desync techniques, inconsistent parsing across CDNs, proxies, application servers, and microservices, and the danger of infrastructure that downgrades HTTP/2 traffic to HTTP/1.1. It presents eliminating HTTP/1.1 as an architectural solution rather than treating the issue as a conventional patchable bug.

## Source excerpt

At Black Hat USA 2025 and DEF CON 33, PortSwigger's Director of Research, James Kettle, unveiled new HTTP desync techniques that prove one thing beyond doubt: HTTP/1.1 is broken, and every organizatio