References https://patents.google.com/patent/CN106789869A/zh https://blog.csdn.net/weixin_46022050/article/details/105741324 https://comate.baidu.com/zh/page/p13u9gp8wvk https://www.aliyun.com/product/news/11390 https://www.cnblogs.com/backlion/p/9007304.html https://cloud.tencent.com/developer/article/2372400 https://vulwiki.readthedocs.io/zh_CN/latest/web/weakpass/ https://developer.mozilla.org/zh-CN/docs/Web/HTTP/Guides/Authentication https://saucer-man.com/information-security/437.html https://zhuanlan.zhihu.com/p/588352820
Related VulnerabilitiesApache HTTP/2 双重释放漏洞(CVE-2026-23918)PoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorPoCCVE-2025-64500: Symfony HttpFoundation - Access Control Bypass via PATH_INFOvulhub httpd apache 解析漏洞PoCcl-te-http-smuggling: Basic CL.TE - HTTP request smugglingPoCte-cl-http-smuggling: Basic TE.CL - HTTP Request SmugglingPoCCVE-2001-0537: Cisco IOS HTTP Configuration - Authentication BypassPoCCVE-2006-1681: Cherokee HTTPD <=0.5 - Cross-Site ScriptingPoCCVE-2014-2323: Lighttpd 1.4.34 SQL Injection and Path TraversalPoCCVE-2017-15715: Apache httpd <=2.4.29 - Arbitrary File UploadPoCCVE-2018-16133: Cybrotech CyBroHttpServer 1.0.3 - Local File InclusionPoCCVE-2018-18778: ACME mini_httpd <1.30 - Local File InclusionPoCCVE-2019-10092: Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting