# CRLF-Powered Desync Attacks: Beheading HTTP Streams

DevFeed: [CRLF-Powered Desync Attacks: Beheading HTTP Streams](<https://devfeed.tech/articles/crlf-powered-desync-attacks-beheading-http-streams-7673.md>)

Original publisher: [Read original article](<https://portswigger.net/research/crlf-powered-desync-attacks>)

Author: Tom Stacey

Published: 2026-08-05T23:30:00Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [browser](<https://devfeed.tech/tags/browser.md>), [http](<https://devfeed.tech/tags/http.md>), [research](<https://devfeed.tech/tags/research.md>), [streams](<https://devfeed.tech/tags/streams.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

A security research paper on turning HTTP header injection into request-smuggling desynchronization attacks, including CRLF-powered desync worms and browser-assisted exploitation techniques.

## Source excerpt

Abstract In this paper we'll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power