Fix CRLF injection in response headers
crlf-header-injection
Raw URL bytes reach your response headers without CRLF stripping, letting an attacker split the response and inject their own headers or body.
Why this matters
Your server passes raw URL bytes into HTTP response headers without sanitizing CRLF characters. An attacker can inject arbitrary headers, enabling response splitting, session fixation via Set-Cookie injection, and XSS via injected Content-Type headers.
CDN and edge
Web servers
Frameworks
Cloudflare
- 1 Cloudflare strips CRLF sequences from URLs by default. If you see this, your origin server is likely exposed directly
- 2 Enable Cloudflare WAF managed rules or ensure all traffic routes through Cloudflare
Does your app still have this?
Scan your domain