http-headers
Safeguard articles tagged "http-headers" — guides, analysis, and best practices for software supply chain and application security.
9 articles
An Uploaded File Can Be Two Formats at Once, and Your Validation Only Checked One
A user's file passes every image validation check your upload handler runs. It is also, independently and simultaneously, a valid HTML document, and browser MIME sniffing can choose to render that instead when your response headers do not stop it.
Your Application's Hostname Should Not Be an Input
To build a reset link your app needs to know its own hostname, and the convenient place to find it is the Host header. That header is supplied by the client, so a stranger decides what goes in the email you send.
When the Cache Key Leaks One User's Page to Another
A personalised response cached under a key that does not include the thing that made it personal. One of the few bugs that discloses one customer's data to another with no attacker involved, and it arrives as a confused support ticket.
Four Silent Ways a Rate Limiter Permits Everything
A forgeable key, a per-instance counter, a fail-open catch block and a fixed window all produce a limiter that runs, logs, appears on the architecture diagram, and blocks nothing. None shows up in the usual test.
Your Edge Appends to X-Forwarded-For, So the First Hop Is Whatever the Caller Typed
Reading the first entry of X-Forwarded-For is reading user input. We captured what our load balancer actually sends, and it explains why a rate limiter can run for months without limiting anything.
Security Headers: A Practical Hardening Guide
Which HTTP security headers actually matter, what each one defends against, and copy-ready configuration to harden a site without breaking it.
Implementing HSTS correctly in Node.js and Express
HSTS has one header and three flags, yet a misconfigured includeSubDomains or a premature preload submission can take a domain offline for months.
Web cache poisoning: attack mechanics and prevention
A 2024 academic scan of the Tranco Top 1000 domains found roughly 17% vulnerable to web cache poisoning — here's how the attack works and how to stop it at the edge.
CSP Meaning in Security: What Content Security Policy Actually Does
CSP in security stands for Content Security Policy, a browser mechanism that tells the page which sources of script, style, and other content it may trust. Here is what it means and how to use it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.