When a reverse proxy or CDN (including Cloudflare) sits in front of the target and rejects malformed Host headers, the X-Forwarded-Host header can sometimes be used to bypass the protection! If the backend middleware reads X-Forwarded-Host and updates the ASGI scope, the malicious value can reach the ASGI and Starlette. #badhost
| Homepage | https://www.x41-dsec.de |
| Github | https://github.com/x41sec |
| https://de.linkedin.com/company/x41 |