Attack  ·  Glossary

Request smuggling (AI infrastructure)

A technique where an attacker crafts an ambiguous web request that gets interpreted differently by two systems in a chain (e.g., a proxy and a server), letting the request 'sneak' past security checks. A flaw of this type in a widely used web framework was found to affect major AI-serving tools like vLLM, LiteLLM, and MCP servers all at once.
One flaw in a shared foundational component can silently compromise the security of dozens of AI products built on top of it, which is why this was fast-tracked onto the US government's actively-exploited vulnerability list.
CISA Known Exploited Vulnerabilities Catalog
Track this in the live feed See how this plays out in real AI security and governance developments.
Open the feed →