CRLF-Powered Desync Attacks: Beheading HTTP Streams
2026-08-06T08:51:51Z•67bb2411022b66681a9a6bab4e864247c057880533c328b3cd48a38a566bd11c
authentication-bypasscache-poisoningcookie-securitycrlf-injectioncsp-bypasscss-exfiltrationheader-injectionhttp-desynchronizationhttp-request-smugglingjwtparser-discrepancysamlsecurity-researchssrftiming-attacksurl-validation-bypassweb-application-securityweb-securitywebsocket
What happened
PortSwigger Research feed containing recent web security research on HTTP request smuggling and desynchronization, authentication bypasses, cookie and parser discrepancies, cache poisoning, SSRF and URL validation bypasses, CSS and CSP-based data exfiltration, JWT or signed-token forgery, WebSocket testing, timing attacks, and related offensive security techniques. The most prominent recent item describes CRLF-powered desync attacks that exploit HTTP header injection and stream parsing inconsistencies. These are research publications and techniques rather than a single confirmed product flaw;—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- 67bb2411022b66681a9a6bab4e864247c057880533c328b3cd48a38a566bd11c
- Enrichment time
- 2026-08-06T08:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.