GitHub
ESC

H2

Tests HTTP/2 protocol-level smuggling vectors. Exploits differences in how HTTP/2 front-ends and HTTP/1.1 back-ends handle request translation.

Tested Payloads

smugglex sends 25+ HTTP/2 smuggling payload variations targeting header injection, pseudo-header manipulation, and protocol downgrade scenarios.

Run

smugglex -c h2 https://target.com