dwisiswant0/crlfuzz
A fast tool to scan CRLF vulnerability written in Go observed · 2026-08-28
Health v2 · maintenance only
66/100
- Activity 97
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2212
- days_rel: n/a
- days_push: 18
- n_releases_24m: 0
Adoption not part of the score
1560 stars · 145 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
CRLFuzz is a fast command-line tool written in Go that scans websites for CRLF (carriage return/line feed) injection vulnerabilities. It supports single URLs, URL lists, stdin input, custom methods, headers, proxies, and concurrency.
Use cases
- scan a website for CRLF injection vulnerabilities
- fuzz a list of URLs for CRLF issues
- check if a target is vulnerable to HTTP response splitting
- bulk scan URLs from stdin during recon
- test CRLF injection through a proxy like Burp
When to choose
- you need a fast, single-purpose CRLF vulnerability scanner
- you want a Go-based CLI that fits into automated recon pipelines
- you need stdin/list-based bulk scanning with concurrency
When to avoid
- you need a general-purpose web vulnerability scanner covering many vulnerability classes
- you need a GUI-based scanning tool
- you need authenticated, session-aware deep crawling
Facets
cli-tool · maturity active
vulnerability-scanning http-client security security penetration-testing web-development windows cli cross-platform crlf-injection vulnerability-scanner go web-security fuzzing command-line linux macos
1 source
- readme: https://github.com/dwisiswant0/crlfuzz · fetched 2026-08-28 · 7054f8ac2de8
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| dwisiswant0/crlfuzz | main | 66 |
For agents
markdown · JSON · MCP: product_card(name="dwisiswant0/crlfuzz")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem