Security Advisory from Mozilla Foundation
2021-37 Header Splitting. https://www.mozilla.org/en-US/security/advisories/mfsa2021-37/ Firefox incorrectly accepted a newline in a HTTP/3 header, interpreting it as two separate headers. This allowed for a header