Skip to content
#

host-header-injection

Here are 9 public repositories matching this topic...

Language: All
Filter by language

Evidence-driven scanner for HTTP request-header vulnerabilities — Host header injection, SSRF, confirmed cache poisoning, access-control bypass, open redirects and virtual-host discovery. Signal over noise, with severity-rated JSON / Markdown / SARIF reports and CI-friendly exit codes.

  • Updated Aug 5, 2026
  • Python

During a security assessment, I identified a Host Header Authentication Bypass vulnerability caused by improper validation of the HTTP Host header. The application trusted user-controlled Host header values during request processing, allowing manipulation of security-sensitive logic.

  • Updated Jul 1, 2026

Improve this page

Add a description, image, and links to the host-header-injection topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the host-header-injection topic, visit your repo's landing page and select "manage topics."

Learn more