This note summarizes local evidence for CRLF injection through runtime-expanded variables in NGINX output paths, with a focus on upstream-friendly reproduction rather than broad parser policy changes.
The narrow question is whether NGINX should refuse to serialize CR/LF/NUL or invalid field names when it is generating HTTP/1.x output from runtime variables.
This is separate from: