Stop building redirects from Host
host-header-redirect
Redirect URLs are built from the Host header, so a crafted request points Location somewhere you do not control. Hardcode your canonical domain.
Why this matters
Your server builds redirect URLs from the Host header. An attacker can only manipulate their own request — the redirect affects only the attacker's session, not other users.
Web servers
Frameworks
Nginx
- 1 Use a hardcoded domain name in redirect directives instead of relying on $host or $http_host
nginx
# BAD: redirect uses client-supplied Host
# return 301 https://$host$request_uri;
# GOOD: redirect uses hardcoded domain
return 301 https://www.example.com$request_uri;Does your app still have this?
Scan your domain