All fixes

Fix CRLF injection in response headers

crlf-header-injection

Raw URL bytes reach your response headers without CRLF stripping, letting an attacker split the response and inject their own headers or body.

Why this matters

Your server passes raw URL bytes into HTTP response headers without sanitizing CRLF characters. An attacker can inject arbitrary headers, enabling response splitting, session fixation via Set-Cookie injection, and XSS via injected Content-Type headers.

Cloudflare

  1. 1 Cloudflare strips CRLF sequences from URLs by default. If you see this, your origin server is likely exposed directly
  2. 2 Enable Cloudflare WAF managed rules or ensure all traffic routes through Cloudflare

Does your app still have this?

Scan your domain