Collected research
CRLF Injection Nested Response Splitting CSP Gadget
A CRLF injection in a response header is nested inside itself: the injected script tag points at a same-origin URL carrying a second response-splitting payload, so a strict script-src self policy is satisfied. Injecting Content-Length or chunked Transfer-Encoding truncates the leftover body so it parses as valid JavaScript, giving XSS.
Record
- Researcher
- Tang Cheuk Hei
- Published by
- Critical Thinking - Bug Bounty Podcast
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Tang Cheuk Hei, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .