CRLF-Powered Desync Attacks: Beheading HTTP Streams
This PortSwigger research by Tom Stacey and Tobia Righi, presented at Black Hat and DEF CON 2026, demonstrates how a simple HTTP header injection primitive using CRLF sequences can be escalated into full-blown desync attacks, including request smuggling, response queue poisoning, browser-powered desync, and even self-propagating desync worms. The technique exploits common misconfigurations in Nginx, OpenResty, and Tengine reverse proxies that decode CRLF characters, allowing attackers to inject their own headers or split requests. The attacks can be triggered through the victim's browser using JavaScript fetch or simple page navigation, bypassing IP and connection-locked protections to steal HTTPOnly cookies and achieve account takeover. The research included real-world case studies across CDN, telecom, payments, retail, streaming, and social media platforms, with a companion Burp extension released for detection.
https://portswigger.net/research/crlf-powered-desync-attacks
Comments
Post a Comment