Stop trusting the null CORS origin
cors-null-origin
The null origin comes from sandboxed iframes and local files, so any page can claim it. Never put null in your Access-Control-Allow-Origin.
Why this matters
Your site allows data sharing with "null" origins, which can be faked using sandboxed iframes. Conditionally exploitable — requires crafting a specific attack page.
Web servers
Frameworks
Nginx
- 1 Do not match 'null' in your origin map
nginx
map $http_origin $cors_origin {
default "";
# Remove this line:
# "null" "null";
"https://app.example.com" $http_origin;
}Does your app still have this?
Scan your domain