Hunting Host Header And Url Parsing Trust

Hunt trust placed in the Host or a forwarded host header and in inconsistently parsed URLs, where the app builds absolute links, keys a cache, routes a request, or matches an allowlist from a header or a parsed URL an attacker can influence or that two components parse differently. Use when a service derives its own external URL from the request, when a cache or router keys on the host, or when a security decision parses a URL. Covers password-reset and verification-link poisoning, cache poisoning, routing to internal virtual hosts, and redirect or fetch allowlist bypass through parser differentials. The attacker-influenced host or ambiguous URL is the source, the link builder, cache key, router, or allowlist parse is the sink, and trusting a host or a parse the attacker controls is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-host-header-and-url-parsing-trust commit 90012c36f4

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-host-header-and-url-parsing-trust