# HTTP Request Smuggling Explained: with seasoned bug bounty hunter NahamSec and world-class researcher James Kettle

DevFeed: [HTTP Request Smuggling Explained: with seasoned bug bounty hunter NahamSec and world-class researcher James Kettle](<https://devfeed.tech/articles/http-request-smuggling-explained-with-seasoned-bug-bounty-hunter-nahamsec-and-world-class-researcher-james-kettle-7731.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/http-request-smuggling-explained-with-seasoned-bug-bounty-hunter-nahamsec-and-world-class-researcher-james-kettle>)

Author: Amelia Coen

Published: 2025-08-05T11:08:29Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [servers](<https://devfeed.tech/topics/servers.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [atlassian](<https://devfeed.tech/tags/atlassian.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [developer](<https://devfeed.tech/tags/developer.md>), [discord](<https://devfeed.tech/tags/discord.md>), [http](<https://devfeed.tech/tags/http.md>), [netflix](<https://devfeed.tech/tags/netflix.md>), [security](<https://devfeed.tech/tags/security.md>), [video](<https://devfeed.tech/tags/video.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The article presents a video in which NahamSec and James Kettle explain HTTP request smuggling, a vulnerability class caused by differences in how front-end and back-end servers interpret HTTP headers. It covers attacks such as session hijacking, cache poisoning, HTTP/2 downgrades, and browser-powered desynchronization, along with real-world cases involving Netflix and Atlassian.

## Source excerpt

Ever wondered how attackers can compromise modern websites by exploiting invisible cracks in HTTP infrastructure to win big bounties? In his latest video, NahamSec walks through the basics of request