National Cyber Warfare Foundation (NCWF)

New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts


0 user ratings
2026-08-20 13:24:13
milo
Red Team (CNA)

Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have introduced a new category of HTTP request smuggling attacks known as “CRLF-Powered Desync Attacks.” This method exploits a frequently overlooked HTTP header injection vulnerability, which can lead to full account takeovers, theft of HTTPOnly cookies, and even the creation of self-propagating desync worms. […]


The post New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Divya

Source: gbHackers
Source Link: https://gbhackers.com/new-crlf-desync-attack/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.