CRLF-Powered Desync Attacks: Beheading HTTP Streams

2026-08-06T08:51:51Z67bb2411022b66681a9a6bab4e864247c057880533c328b3cd48a38a566bd11c
authentication-bypasscache-poisoningcookie-securitycrlf-injectioncsp-bypasscss-exfiltrationheader-injectionhttp-desynchronizationhttp-request-smugglingjwtparser-discrepancysamlsecurity-researchssrftiming-attacksurl-validation-bypassweb-application-securityweb-securitywebsocket

What happened

PortSwigger Research feed containing recent web security research on HTTP request smuggling and desynchronization, authentication bypasses, cookie and parser discrepancies, cache poisoning, SSRF and URL validation bypasses, CSS and CSP-based data exfiltration, JWT or signed-token forgery, WebSocket testing, timing attacks, and related offensive security techniques. The most prominent recent item describes CRLF-powered desync attacks that exploit HTTP header injection and stream parsing inconsistencies. These are research publications and techniques rather than a single confirmed product flaw;—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
67bb2411022b66681a9a6bab4e864247c057880533c328b3cd48a38a566bd11c
Enrichment time
2026-08-06T08:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.