Preliminary research
CRLF-Powered Desync Attacks: Beheading HTTP Streams
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
When Nginx's proxy_pass includes $uri the path is normalised and URL-decoded, so %0d%0a in it injects headers or whole requests into the upstream request. Injecting Transfer-Encoding beside the real Content-Length gives a CL.TE desync, and two CRLFs split the request for response queue poisoning inside a CDN and a payment provider's cluster. An injected Expect: 100-continue exposes blind tunnelling, and browser fetch can drive the attack, making the desync wormable.
Record
- Researcher
- Tom Stacey and Tobia Righi
- Published by
- PortSwigger Research
- Date
- Topic
- HTTP
In the archive
Related sources
- CRLF-Powered Desync Attacks: Beheading HTTP Streams
- CRLF-Powered Desync Attacks: Beheading HTTP Streams (Slides) Whitepaper
- Scanner Repository
- Toolkit Repository
- Coauthor's version
Tags
This page is the archive's own catalogue record. The research is the work of Tom Stacey and Tobia Righi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .