CRLF-Powered Desync Attacks: Beheading HTTP Streams
2026-08-06T20:51:47Z•25453062a06acd7e4e727b6e19c9216b5a513a4aac776b792b2724f91384914f
application-securityauthentication-bypassbrowser-securitycache-poisoningcookie-securitycrlf-injectioncsp-bypasscss-exfiltrationhttp-desynchronizationhttp-header-injectionhttponly-bypassidorjwtparser-discrepancyrequest-smugglingsamlsession-theftssrftiming-attackstoken-forgeryurl-validationwaf-bypassweb-securitywebsocketxss
What happened
PortSwigger Research feed covering novel web-security attack techniques and testing tools, including CRLF-powered HTTP desynchronization, SAML parser inconsistencies enabling authentication bypass, cookie-prefix and HttpOnly bypasses, URL-validation weaknesses, cache poisoning, CSS and CSP data exfiltration, request smuggling, token forgery, and browser or parser discrepancies. The material is primarily research and guidance rather than a single confirmed vulnerability, but several topics describe potentially critical impacts such as session theft, SSRF, administrative access, and HTTP stream/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- 25453062a06acd7e4e727b6e19c9216b5a513a4aac776b792b2724f91384914f
- Enrichment time
- 2026-08-06T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.