All fixes

Stop building redirects from Host

host-header-redirect

Redirect URLs are built from the Host header, so a crafted request points Location somewhere you do not control. Hardcode your canonical domain.

Why this matters

Your server builds redirect URLs from the Host header. An attacker can only manipulate their own request — the redirect affects only the attacker's session, not other users.

Nginx

  1. 1 Use a hardcoded domain name in redirect directives instead of relying on $host or $http_host
nginx
# BAD: redirect uses client-supplied Host
# return 301 https://$host$request_uri;

# GOOD: redirect uses hardcoded domain
return 301 https://www.example.com$request_uri;

Does your app still have this?

Scan your domain