Web Hack List

Later archive addition

Security Bugs: SSRF via Request Splitting

The post demonstrates how an SSRF primitive can become HTTP request splitting when a URL-handling stack accepts attacker-controlled carriage returns or line feeds. Injected request bytes let the attacker address additional internal resources beyond the URL the application intended to fetch.

Record

Researcher
@rfkelly

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @rfkelly, first published at the original source. Preserved copies are kept so the citation survives its host.