Top 10 winner
Making HTTP header injection critical via response queue poisoning
Turns a CRLF header injection into a full HTTP desync: the injected headers cleanly terminate the first request and set Connection keep-alive, so a second attacker-controlled request can be appended. That poisons the back-end response queue, delivering other users' responses to the attacker, or poisons a shared cache.
Record
- Researcher
- James Kettle
- Published by
- PortSwigger Research
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .