Skip to content
Vulnerability field guide

Host Header Injection

Applications that trust the Host header to build absolute URLs can be tricked into emailing attacker-controlled reset links and poisoning caches. Here is how it works and how to validate your way out.

2 articles 8 min total Overview to advanced techniques

Host Header Injection techniques

1 focused deep-dive
  1. 02 Cache PoisoningWeb Cache Poisoning via the Host Header 5 min