The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
https://tom.vg/papers/heist_blackhat2016.pdf
http://www.securitytracker.com/id/1036746
http://www.securitytracker.com/id/1036745
http://www.securitytracker.com/id/1036744
http://www.securitytracker.com/id/1036743
http://www.securitytracker.com/id/1036742
http://www.securitytracker.com/id/1036741