Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageResearch Desk
Research

CRLF-Powered Desync Attacks: Beheading HTTP Streams

PortSwigger demonstrates that CRLF injection in HTTP headers can be weaponised into full HTTP desync attacks, fundamentally reframing header injection as a critical vulnerability class.

Summary written by editorial AI · Source link below

Filed by PortSwigger Research1 min readRead at source ↗

Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power

Editorial Analysis

Why it matters

Organisations that have deprioritised HTTP header injection as low-severity need to reassess — when chained with desync techniques, it can bypass WAFs and compromise backend systems.

What to do

Re-classify CRLF/header injection findings in your vulnerability management system and prioritise remediation of exposed HTTP header construction paths.

Board brief

HTTP header injection, long considered low-risk, can now be weaponised into attacks that bypass web application firewalls and compromise backend infrastructure.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at PortSwigger Research

External link — opens at PortSwigger Research in a new tab.

§
Continue with

More from the Research Desk