smugglex

HAHWUL Publisher

Install latest/stable of smugglex

Ubuntu 16.04 or later?

Make sure snap support is enabled in your Desktop store.


Install using the command line

sudo snap install smugglex

Don't have snapd? Get set up for snaps.

Channel Version Published

Details for smugglex

Package name

  • smugglex

License

  • MIT

Last updated

  • 6 June 2026 - latest/stable

Report a Snap Store violation

Share this snap

Generate an embeddable card to be shared on external websites.

Rust-powered HTTP Request Smuggling Scanner.

Smugglex is a security testing tool that detects HTTP Request Smuggling vulnerabilities in web applications. The tool tests for multiple attack types including CL.TE, TE.CL, TE.TE, H2C, and H2 smuggling.

HTTP Request Smuggling exploits differences in how front-end and back-end servers parse HTTP requests. When servers disagree on request boundaries, attackers can smuggle malicious requests through security controls. This leads to security vulnerabilities such as bypassing firewalls, poisoning caches, and accessing unauthorized resources.

Key Features:

  • Detect multiple attack types: CL.TE, TE.CL, TE.TE, H2C, and H2
  • Test 40+ variations of Transfer-Encoding header obfuscations
  • Support HTTP/2 protocol-level desync detection
  • Export vulnerable payloads for manual verification
  • Save scan results in JSON format
  • Read URLs from stdin for pipeline integration
  • Configure custom headers, cookies, and virtual hosts

Install smugglex on your Linux distribution

Choose your Linux distribution to get detailed installation instructions. If yours is not shown, get more details on the installing snapd documentation.