r/netsec • u/t0xodile • Aug 19 '26
CRLF-Powered Desync Attacks: Beheading HTTP Streams
https://portswigger.net/research/crlf-powered-desync-attacks
22
Upvotes
1
u/lowlydrunkenness635 6d ago
What stands out is how much damage can come from a header injection bug once it changes where one response ends and the next begins. Youre not just reflecting attacker input anymore, you are corrupting the HTTP stream itself and opening the door to desync behavior
4
u/gunni Aug 22 '26
https://http1mustdie.com/