Safeguard
Tag

http-headers

Safeguard articles tagged "http-headers" — guides, analysis, and best practices for software supply chain and application security.

9 articles

Application Security

An Uploaded File Can Be Two Formats at Once, and Your Validation Only Checked One

A user's file passes every image validation check your upload handler runs. It is also, independently and simultaneously, a valid HTML document, and browser MIME sniffing can choose to render that instead when your response headers do not stop it.

Sep 18, 20266 min read
Application Security

Your Application's Hostname Should Not Be an Input

To build a reset link your app needs to know its own hostname, and the convenient place to find it is the Host header. That header is supplied by the client, so a stranger decides what goes in the email you send.

Sep 18, 20265 min read
Application Security

When the Cache Key Leaks One User's Page to Another

A personalised response cached under a key that does not include the thing that made it personal. One of the few bugs that discloses one customer's data to another with no attacker involved, and it arrives as a confused support ticket.

Sep 18, 20266 min read
Application Security

Four Silent Ways a Rate Limiter Permits Everything

A forgeable key, a per-instance counter, a fail-open catch block and a fixed window all produce a limiter that runs, logs, appears on the architecture diagram, and blocks nothing. None shows up in the usual test.

Sep 17, 20266 min read
Application Security

Your Edge Appends to X-Forwarded-For, So the First Hop Is Whatever the Caller Typed

Reading the first entry of X-Forwarded-For is reading user input. We captured what our load balancer actually sends, and it explains why a rate limiter can run for months without limiting anything.

Sep 17, 20267 min read
Security

Security Headers: A Practical Hardening Guide

Which HTTP security headers actually matter, what each one defends against, and copy-ready configuration to harden a site without breaking it.

Jul 15, 20265 min read
Application Security

Implementing HSTS correctly in Node.js and Express

HSTS has one header and three flags, yet a misconfigured includeSubDomains or a premature preload submission can take a domain offline for months.

Jul 15, 20266 min read
Application Security

Web cache poisoning: attack mechanics and prevention

A 2024 academic scan of the Tranco Top 1000 domains found roughly 17% vulnerable to web cache poisoning — here's how the attack works and how to stop it at the edge.

Jul 8, 20266 min read
Security

CSP Meaning in Security: What Content Security Policy Actually Does

CSP in security stands for Content Security Policy, a browser mechanism that tells the page which sources of script, style, and other content it may trust. Here is what it means and how to use it.

Apr 22, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.