Later archive addition
Security Bugs: SSRF via Request Splitting
The post demonstrates how an SSRF primitive can become HTTP request splitting when a URL-handling stack accepts attacker-controlled carriage returns or line feeds. Injected request bytes let the attacker address additional internal resources beyond the URL the application intended to fetch.
Record
- Researcher
- @rfkelly
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @rfkelly, first published at the original source. Preserved copies are kept so the citation survives its host.