Skip to content
Vulnerability field guide

CRLF Injection

A carriage return and a line feed are all it takes to inject headers, forge cookies and poison caches. Here is how CRLF injection leads to HTTP response splitting, and how to shut it down.

1 article 5 min total Overview to advanced techniques