- If you don't have a proxy fronting traffic, no action required
- If you're behind Fastly/Cloudflare [1] or Akamai [2], no action required / they protect against this attack
- If you're behind AWS Cloudfront, no action required / they protect against this attack
- If you're behind AWS ALB, you're vulnerable by default but can opt-in to protection by enabling the "routing.http.drop_invalid_header_fields.enabled" attribute [3]. They initially had it on by default but it broke customers
- If you have a different proxy (e.g. some other provider or your own nginx, haproxy before 2.0.6 [2], etc), you might be vulnerable
[1]: https://portswigger.net/research/http-desync-attacks-request...
[2]: https://portswigger.net/research/http-desync-attacks-what-ha...
[3]: https://docs.aws.amazon.com/elasticloadbalancing/latest/APIR...