http-host-header-attacks

Installation
SKILL.md

SKILL: HTTP Host Header Attacks — Injection & Routing Abuse

AI LOAD INSTRUCTION: Covers Host header injection for password reset poisoning, cache poisoning, SSRF via routing, and virtual host bypass. Includes bypass techniques for Host validation and framework-specific behaviors. Base models often miss the double-Host trick, absolute-URI override, and connection-state attacks.

0. RELATED ROUTING


1. ATTACK SURFACE

The Host header is used by web applications and infrastructure for:

Related skills
Installs
468
GitHub Stars
620
First Seen
Apr 9, 2026