What MITRE CAPEC-105: HTTP Request Splitting (Detailed Attack Pattern - High Severity) requires
MITRE CAPEC-105 (HTTP Request Splitting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages by different intermediary HTTP agents (e.g., load balancer, reverse proxy, web caching proxies, application firewalls, etc.) to split a single HTTP request into multiple unauthorized and malicious HTTP requests to a back-end HTTP agent (e.g., web server). Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-74, CWE-113, CWE-138, CWE-436.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/105.html
SHA-256 integrity: ef14537b0a87c45c25dc3086d18a5e9caa5f44de841ad13d92be3d68ea611256
Primary Citations — 11 traced to source
- MITRE CAPEC-105: HTTP Request Splitting (https://capec.mitre.org/data/definitions/105.html)
- CWE-74: underlying weakness (http://cwe.mitre.org/data/definitions/74.html)
+ 9 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-capec-capec-105-http-request-splitting.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-capec-capec-105-http-request-splitting.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-capec-capec-105-http-request-splitting
- Back to registry: Browse all 10,085 compliance nodes