Stop reflecting the Host header
host-header-poisoning
Your server copies the client's Host header into the response body. Use the validated host your proxy sets, not the raw value the client sent.
CDN and edge
Web servers
Frameworks
Cloudflare
- 1 Cloudflare normalizes the Host header by default. If you see this finding, your origin server is likely exposed directly
- 2 Ensure all traffic goes through Cloudflare by blocking direct origin access
Does your app still have this?
Scan your domain