Burp Suite User Forum

Create new post

Injection of line break (\r\n) into :path pseudo header gets stripped

Itay | Last updated: Sep 22, 2023 10:24AM UTC

While doing the lab "Web cache poisoning via HTTP/2 request tunnelling" I've noticed that the \r\n bytes are getting stripped when issuing a request in Repeater. Confirmed this issue in the Logger: Intended :path value: / HTTP/1.1 Host: lab.domain Resulted request: / HTTP/1.1Host: lab.domain Tried to reset settings and unchecked Normalize HTTP/1 line endings just in case. This issue was observed only in with the :path pseudo header.

Michelle, PortSwigger Agent | Last updated: Sep 25, 2023 10:35AM UTC

Thanks for taking the time to get in touch and let us know about this. We've replicated this here, so have raised a bug to discuss further with the developers.

meownsoon | Last updated: Dec 01, 2023 01:39PM UTC

Hi! Any update on this issue? It seems to be still present in the latest version.

Michelle, PortSwigger Agent | Last updated: Dec 01, 2023 02:37PM UTC

Hi A fix for this has been released to Early Adopter version 2023.11.1 onwards, so will be coming to the stable release channel soon.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.