A fast tool to scan CRLF vulnerability written in Go
-
Updated
Aug 28, 2026 - Go
A fast tool to scan CRLF vulnerability written in Go
Python tool that probes websites for open redirection via headers, JavaScript, and meta-tag refresh, pulls candidate URLs from the Wayback Machine, and checks CRLF injection and DOM XSS.
The most powerful CRLF injection (HTTP Response Splitting) scanner.
CRLF and open redirect fuzzer
A CRLF ( Carriage Return Line Feed ) Injection attack occurs when a user manages to submit a CRLF into an application. This is most commonly done by modifying an HTTP parameter or URL.
CRLF Bug scanner for WebPentesters and Bugbounty Hunters
使用java编写的CRLF-Injection-burp被动扫描插件
📧 [Research] E-Mail Injection: Vulnerable applications
CRLF Detection based on @BlackFan 's work See link below
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSec rule pack, remote probe, on-host IOC scanner, and per-tier RE snapshot collector. GPL v2.
CRLF Injection Payload List
This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug
Want to keep your Web application from getting hacked? Here's how to get serious about secure apps. So let's do it! Open Friday, Aug 2016 - Presentation Notes.
CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection vulnerabilities through payload-based testing and HTTP header analysis.
CRLF injection scanner
This Bash script is a CRLF injection vulnerability scanner called REX. It checks for various CRLF injection vulnerabilities in a given URL by sending multiple payloads and analyzing the response
A web application to demonstrate log injection vulnerability and input sanitization methods to mitigate the vulnerability
This is a automation tools for checking crlf vulns
CVE-2026-35517 Pi-hole FTLDNS Remote Code Execution via Newline Injection (CVSS 8.8). Python & Nmap NSE detection scripts with full technical breakdown. A newline character in the dns.upstreams parameter gives authenticated attackers command execution on the host. Five related injection vectors all patched in FTL v6.6.
To associate your repository with the crlf-injection topic, visit your repo's landing page and select "manage topics."