CRLF-Powered Desync Attacks: Beheading HTTP Streams
PortSwigger demonstrates that CRLF injection in HTTP headers can be weaponised into full HTTP desync attacks, fundamentally reframing header injection as a critical vulnerability class.
Summary written by editorial AI · Source link below
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
Editorial Analysis
Organisations that have deprioritised HTTP header injection as low-severity need to reassess — when chained with desync techniques, it can bypass WAFs and compromise backend systems.
Re-classify CRLF/header injection findings in your vulnerability management system and prioritise remediation of exposed HTTP header construction paths.
HTTP header injection, long considered low-risk, can now be weaponised into attacks that bypass web application firewalls and compromise backend infrastructure.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at PortSwigger Research in a new tab.
More from the Research Desk
- 39 New Methods That Compromise Passkey Authentication3d
- Security Vulnerability in a Voting System3d
- Selfie-Capture Dynamics as an Auxiliary Signal Against Deepfakes and Injection Attacks for Mobile Identity Verification4d
- How Reliable Is the Multi-Input Heuristic for Bitcoin Address Clustering in Law Enforcement Contexts?4d
- Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks4d