Vulnerability field guide

Host Header Injection

Applications that trust the Host header to build absolute URLs can be tricked into emailing attacker-controlled reset links and poisoning caches. Here is how it works and how to validate your way out.

2 articles8 min totalOverview to advanced techniques
Start hereHost: evil.attacker.com
Step 01 · Start with the overview
Host Header Injection3 min read

Host Header Injection: How a Spoofed Header Hijacks Password-Reset Links

Applications that trust the Host header to build absolute URLs can be tricked into emailing attacker-controlled reset links and poisoning caches. Here is how it works and how to validate your way out.

Read the overview
Continue the field guide

Host Header Injection techniques

1 focused deep-dives
  1. 02Cache PoisoningWeb Cache Poisoning via the Host Header5 min