Web Hack List

Preliminary research

CRLF-Powered Desync Attacks: Beheading HTTP Streams

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

When Nginx's proxy_pass includes $uri the path is normalised and URL-decoded, so %0d%0a in it injects headers or whole requests into the upstream request. Injecting Transfer-Encoding beside the real Content-Length gives a CL.TE desync, and two CRLFs split the request for response queue poisoning inside a CDN and a payment provider's cluster. An injected Expect: 100-continue exposes blind tunnelling, and browser fetch can drive the attack, making the desync wormable.

Record

Researcher
Tom Stacey and Tobia Righi
Published by
PortSwigger Research
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Tom Stacey and Tobia Righi, first published at the original source. Preserved copies are kept so the citation survives its host.