Description
CR/LF from input can manipulate response headers when it reaches a header or cookie and a server, proxy or recipient interprets it as a message boundary. Some servers reject invalid values, so the effect depends on the actual processing path.
Potential impact
- Cache poisoning, cookie injection or modified responses.
Remediation
Validate header and cookie syntax and reject values containing CR/LF. If removal is required, separately validate the field's allowed characters and length, and keep the server's built-in header validation enabled.
Examples
Before
csharp
Response.Headers["X-Name"] = value;
After
This excerpt assumes value is non-null. It removes only CR/LF; other controls, length and header-specific syntax still require validation.
csharp
Response.Headers["X-Name"] = value.Replace("\r", "").Replace("\n", "");
Explanation:
- Before: Response splitting is possible where the processing path interprets input CR/LF as response boundaries.
- After: Reject or remove CR and LF before placing input in headers or cookies.