# HTTP/1.1 Must Die: What This Means for Bug Bounty Hunters

DevFeed: [HTTP/1.1 Must Die: What This Means for Bug Bounty Hunters](<https://devfeed.tech/articles/http-1-1-must-die-what-this-means-for-bug-bounty-hunters-7728.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/http-1-1-must-die-what-this-means-for-bug-bounty-hunters>)

Author: Andrzej Matykiewicz

Published: 2025-08-06T22:23:28Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [http](<https://devfeed.tech/tags/http.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article argues that HTTP request smuggling, or desync attacks, remains a major web-security risk because HTTP/1.1 request boundaries can be interpreted inconsistently across interconnected systems. It presents upstream HTTP/2 as the solution and frames desync testing as a high-value opportunity for bug bounty hunters.

## Source excerpt

At Black Hat USA and DEFCON 2025, PortSwigger's Director of Research, James Kettle, issued a stark warning: request smuggling isn't dying out, it's evolving and thriving. Despite years of defensive ef