
CRLF Header Injection Flaws Enable HTTP Request Smuggling and Cookie Theft
A newly disclosed CRLF header injection vulnerability, often treated as a low-impact flaw, can be exploited to enable HTTP request smuggling, response queue poisoning, cross-site scripting, and session cookie theft. Tom Stacey demonstrates that differences in how proxies, CDNs, and backend applications parse HTTP traffic can transform an injected newline into a critical desynchronization vulnerability. […]
The post CRLF Header Injection Flaws Enable HTTP Request Smuggling and Cookie Theft appeared first on Cyber Security News.