CRLF-Powered Desync Attacks: Beheading HTTP Streams

This PortSwigger research by Tom Stacey and Tobia Righi, presented at Black Hat and DEF CON 2026, demonstrates how a simple HTTP header injection primitive using CRLF sequences can be escalated into full-blown desync attacks, including request smuggling, response queue poisoning, browser-powered desync, and even self-propagating desync worms. The technique exploits common misconfigurations in Nginx, OpenResty, and Tengine reverse proxies that decode CRLF characters, allowing attackers to inject their own headers or split requests. The attacks can be triggered through the victim's browser using JavaScript fetch or simple page navigation, bypassing IP and connection-locked protections to steal HTTPOnly cookies and achieve account takeover. The research included real-world case studies across CDN, telecom, payments, retail, streaming, and social media platforms, with a companion Burp extension released for detection. 

https://portswigger.net/research/crlf-powered-desync-attacks

Comments

Popular posts from this blog

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know

Critical OpenSSH Flaws Enable MITM and DoS Attacks

MITRE ATT&CK v19 Redefines How Defenders Model Modern Threats