"cybersecurity""web-security""security"
6 min readCRLF Injection: The Two Characters That Can Hijack Your HTTP Responses 🔪
Meet \\\r\\\n — the two most underrated troublemakers in web security. CRLF injection can split your HTTP responses, inject fake headers, and even pull off XSS. Spoiler: your framework probably saves you, but only if you know when to let it.
Mar 14, 2026