All fixes

Stop trusting X-Forwarded-Host

host-header-xfh

You trust X-Forwarded-Host from the client, so password reset links can be aimed at an attacker's domain. Strip it at the edge and set it yourself.

Why this matters

Your server trusts the X-Forwarded-Host header and uses it to generate links. An attacker can manipulate password reset emails and other system-generated links to point to their own domain, enabling token theft and phishing.

Cloudflare

  1. 1 Cloudflare does not forward X-Forwarded-Host by default. If you see this, check your origin server configuration
  2. 2 Ensure your origin ignores or strips X-Forwarded-Host from incoming requests

Does your app still have this?

Scan your domain