Five desync classes
Tests CL.TE, TE.CL, TE.TE, H2C and H2 request smuggling.
Request Smuggling Scanner · Rust
A Rust-powered HTTP request smuggling scanner. Detects CL.TE, TE.CL, TE.TE, H2C and H2 desync with clean JSON output and proper exit codes for CI.
Capabilities
Five smuggling classes, raw-request replay and machine-readable output with exit codes designed to gate a build.
Tests CL.TE, TE.CL, TE.TE, H2C and H2 request smuggling.
Replay raw requests exported straight from Burp Suite.
Machine-readable output drops cleanly into automation and pipelines.
0 clean, 1 vulnerable, 2 error — gate a build on the result.
Pipe a list of targets and scan them in one pass.
Inject custom headers, including OAST collaborator hosts.
Quickstart
Illustrative output.
Install SmuggleX and add it to your security pipeline.