Web Hack List

Preliminary research

CRLF-Powered Desync Attacks: Beheading HTTP Streams

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

When Nginx's proxy_pass includes $uri the path is normalised and URL-decoded, so %0d%0a in it injects headers or whole requests into the upstream request. Injecting Transfer-Encoding beside the real Content-Length gives a CL.TE desync, and two CRLFs split the request for response queue poisoning inside a CDN and a payment provider's cluster. An injected Expect: 100-continue exposes blind tunnelling, and browser fetch can drive the attack, making the desync wormable.

Record

Researcher
Tom Stacey and Tobia Righi
Published by
PortSwigger Research
Date
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Tom Stacey and Tobia Righi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .