Preliminary research
CRLF-Powered Desync Attacks: Beheading HTTP Streams
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
When Nginx's proxy_pass includes $uri the path is normalised and URL-decoded, so %0d%0a in it injects headers or whole requests into the upstream request. Injecting Transfer-Encoding beside the real Content-Length gives a CL.TE desync, and two CRLFs split the request for response queue poisoning inside a CDN and a payment provider's cluster. An injected Expect: 100-continue exposes blind tunnelling, and browser fetch can drive the attack, making the desync wormable.
Record
- Researcher
- Tom Stacey and Tobia Righi
- Published by
- PortSwigger Research
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Tom Stacey and Tobia Righi, first published at the original source. Preserved copies are kept so the citation survives its host.