Stop trusting X-Forwarded-Host
host-header-xfh
You trust X-Forwarded-Host from the client, so password reset links can be aimed at an attacker's domain. Strip it at the edge and set it yourself.
Why this matters
Your server trusts the X-Forwarded-Host header and uses it to generate links. An attacker can manipulate password reset emails and other system-generated links to point to their own domain, enabling token theft and phishing.
CDN and edge
Web servers
Frameworks
Cloudflare
- 1 Cloudflare does not forward X-Forwarded-Host by default. If you see this, check your origin server configuration
- 2 Ensure your origin ignores or strips X-Forwarded-Host from incoming requests
Does your app still have this?
Scan your domain