CRLF-Powered Desync Attacks: Beheading HTTP Streams

2026-08-06T20:51:47Z25453062a06acd7e4e727b6e19c9216b5a513a4aac776b792b2724f91384914f
application-securityauthentication-bypassbrowser-securitycache-poisoningcookie-securitycrlf-injectioncsp-bypasscss-exfiltrationhttp-desynchronizationhttp-header-injectionhttponly-bypassidorjwtparser-discrepancyrequest-smugglingsamlsession-theftssrftiming-attackstoken-forgeryurl-validationwaf-bypassweb-securitywebsocketxss

What happened

PortSwigger Research feed covering novel web-security attack techniques and testing tools, including CRLF-powered HTTP desynchronization, SAML parser inconsistencies enabling authentication bypass, cookie-prefix and HttpOnly bypasses, URL-validation weaknesses, cache poisoning, CSS and CSP data exfiltration, request smuggling, token forgery, and browser or parser discrepancies. The material is primarily research and guidance rather than a single confirmed vulnerability, but several topics describe potentially critical impacts such as session theft, SSRF, administrative access, and HTTP stream/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
25453062a06acd7e4e727b6e19c9216b5a513a4aac776b792b2724f91384914f
Enrichment time
2026-08-06T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.