Skip to content

Conversation

@Ayoub-Mabrouk
Copy link
Contributor

Verify that req.host ignores comma-separated X-Forwarded-Host values
when trust proxy is disabled, ensuring security by using Host header
instead of potentially malicious forwarded headers

…st proxy disabled

Verify that req.host ignores comma-separated X-Forwarded-Host values
when trust proxy is disabled, ensuring security by using Host header
instead of potentially malicious forwarded headers.
@Ayoub-Mabrouk Ayoub-Mabrouk force-pushed the test/add-req-host-ignore-comma-separated branch from 475b00c to 1f860fb Compare November 10, 2025 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant