tl;dr
- CRLF Injection in Headed Key in Werkzeug 
headers.set - Using CRLF Injection at 
/?user=to Get XSS at/helloworld - Make the admin visit 
/?user=<PAYLOAD>and/helloworldusing cache poison or bug in regex(uninteded) 
tl;dr
headers.set/?user= to Get XSS at /helloworld/?user=<PAYLOAD> and /helloworld using cache poison or bug in regex(uninteded)tl;dr
tl;dr
Header().Set() methodTiming-Allow-Origin header