Skip to content
Back to skills

Web Host Header

ASecurity

Host header injection — abuse a trusted Host/X-Forwarded-Host to poison password-reset links, routing, and caches. Load when the app builds absolute URLs from the request host, on password-reset flows, or behind a proxy/CDN. Signals: reset emails with links, X-Forwarded-Host reflected, virtual hosting, cache in front.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentsrustgosecurity

Works with

  • cli

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add NoorQureshi/SploitAgent --skill web-host-header --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Web Host Header?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Web Host Header
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-web-host-header/badge)](https://www.skillsdirectory.com/skills/noorqureshi-web-host-header)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: web-host-header
description: >
  Host header injection — abuse a trusted Host/X-Forwarded-Host to poison password-reset links,
  routing, and caches. Load when the app builds absolute URLs from the request host, on
  password-reset flows, or behind a proxy/CDN. Signals: reset emails with links, X-Forwarded-Host
  reflected, virtual hosting, cache in front.
domain: web
type: technique
stability: learning
modes: [bugbounty, pentest]
severity: medium
owasp: [A05:2021-Security-Misconfiguration]
cwe: [CWE-644]
tools: [burp]
schema_version: 1
---

# Host header injection

## When it applies
The server trusts the `Host` (or `X-Forwarded-Host`) header to build absolute URLs, decide
routing, or key a cache. Classic impact: password-reset poisoning (the reset link points at your
domain, so the victim's token comes to you).

## Why it works
Frameworks read the request host to construct links (`https://{host}/reset?token=…`). The host is
attacker-controlled, so if it isn't validated against an allowlist, you control where generated
links point — and where secrets in them land.

## Method
1. **Reset poisoning**: trigger a password reset for a victim; intercept and set `Host:
   attacker.com` (or add `X-Forwarded-Host: attacker.com`). If the emailed link uses your host,
   the victim's click sends their reset token to you → account takeover.
2. **Routing/authz**: try `Host:` of an internal vhost (`admin.internal`) to reach restricted apps
   behind the proxy; test `X-Forwarded-Host`, `X-Forwarded-Server`, `X-Host`, dup Host headers.
3. **Cache poisoning**: if the host is reflected into a cached response, combine with
   `web-cache-poisoning` to serve your host to other users.
4. **Validation bypass**: absolute-URL Host (`Host: attacker.com`), `Host: victim.com:@attacker.com`,
   line-wrapping, and duplicate headers (front-end vs back-end pick different ones).

## Gotchas
- Many stacks now validate Host — confirm the generated link/response actually uses your value.
- `X-Forwarded-Host` often wins even when `Host` is validated — always test it separately.
- Reset poisoning needs the app to email a host-derived link; verify by reading the email/link.

## Verify success
A password-reset (or other) link built with your attacker host, or an internal vhost reached, or
a poisoned cached response served to a clean request.

## References
PortSwigger Host header attacks labs; OWASP host-header injection.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…