Skip to content

fix: prevent Host header bypass vulnerability - #58

Merged
ammario merged 4 commits into
mainfrom
url-security
Sep 21, 2025
Merged

fix: prevent Host header bypass vulnerability#58
ammario merged 4 commits into
mainfrom
url-security

Conversation

@ammario

Copy link
Copy Markdown
Member

Summary

This PR fixes a security vulnerability where an attacker could bypass proxy restrictions by sending requests with mismatched Host headers, as described in #57.

The Vulnerability

The issue allowed sending a request to one domain (e.g., api.anthropic.com) while setting the Host header to another domain (e.g., evil.com). This could cause CDNs like CloudFlare to route the request to the attacker's server instead of the intended destination, potentially enabling:

  • Data exfiltration from CloudFlare-protected sites
  • Bypassing proxy restrictions for protected domains

The Fix

Modified prepare_upstream_request() in src/proxy.rs to ensure the Host header always matches the URI authority. The fix:

  1. Extracts the authority (domain:port) from the target URI
  2. Overwrites any existing Host header with the correct value
  3. Applies to both HTTP and HTTPS requests

Testing

Added comprehensive test coverage in tests/weak_integration.rs:

  • ✅ HTTP requests with mismatched Host headers are corrected
  • ✅ HTTPS requests with mismatched Host headers are corrected
  • ✅ Legitimate matching Host headers work normally
  • ✅ Host headers with port numbers are handled correctly
  • ✅ Requests without explicit Host headers get the correct default

Verification

# Run the security test
cargo test --test weak_integration test_host_header_security
# Run all tests
cargo test

All tests pass and the code meets quality standards (clippy, formatting).

Fixes#57

🤖 Generated with Claude Code

ammarioand others added 4 commits September 21, 2025 11:12
This commit fixes a security vulnerability where an attacker could bypass
proxy restrictions by sending requests with mismatched Host headers.
The vulnerability allowed sending a request to one domain (e.g., api.anthropic.com)
while setting the Host header to another domain (e.g., evil.com), which could
cause CDNs like CloudFlare to route the request to the attacker's server.
Changes:
- Modified prepare_upstream_request() to ensure Host header always matches URI authority
- Added comprehensive test coverage in weak_integration.rs
- Validates both HTTP and HTTPS requests
This prevents data exfiltration and unauthorized access to protected domains.
Fixes#57
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Simplified the test to clearly demonstrate the vulnerability and fix by:
- Running the same curl command directly (shows evil.com passes through)
- Running it through httpjail (shows it's corrected to httpbin.org)
This makes it clearer that httpjail prevents the Host header bypass
attack that would otherwise be possible.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Added a TODO note documenting future improvement to use the type system
to ensure all request information passed to upstream has been validated
by the RuleEngine. This would provide compile-time guarantees that
security checks cannot be bypassed.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
@ammario
ammario marked this pull request as ready for review September 21, 2025 16:38

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadtests/weak_integration.rs
@ammario
ammario merged commit 664cd1a into mainSep 21, 2025
6 checks passed
@ammario
ammario deleted the url-security branch September 21, 2025 17:09
@ammario

Copy link
Copy Markdown
MemberAuthor

Created issue #59 to track the TODO for using the type system to prevent request validation bypasses. This would make security vulnerabilities like the Host header bypass impossible at compile time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Full proxy bypass on any CloudFlare (or other proxy service) requests

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix: prevent Host header bypass vulnerability by ammario · Pull Request #58 · coder/httpjail · GitHub
Skip to content

fix: prevent Host header bypass vulnerability - #58

Merged
ammario merged 4 commits into
mainfrom
url-security
Sep 21, 2025
Merged

fix: prevent Host header bypass vulnerability#58
ammario merged 4 commits into
mainfrom
url-security

Conversation

@ammario

Copy link
Copy Markdown
Member

Summary

This PR fixes a security vulnerability where an attacker could bypass proxy restrictions by sending requests with mismatched Host headers, as described in #57.

The Vulnerability

The issue allowed sending a request to one domain (e.g., api.anthropic.com) while setting the Host header to another domain (e.g., evil.com). This could cause CDNs like CloudFlare to route the request to the attacker's server instead of the intended destination, potentially enabling:

  • Data exfiltration from CloudFlare-protected sites
  • Bypassing proxy restrictions for protected domains

The Fix

Modified prepare_upstream_request() in src/proxy.rs to ensure the Host header always matches the URI authority. The fix:

  1. Extracts the authority (domain:port) from the target URI
  2. Overwrites any existing Host header with the correct value
  3. Applies to both HTTP and HTTPS requests

Testing

Added comprehensive test coverage in tests/weak_integration.rs:

  • ✅ HTTP requests with mismatched Host headers are corrected
  • ✅ HTTPS requests with mismatched Host headers are corrected
  • ✅ Legitimate matching Host headers work normally
  • ✅ Host headers with port numbers are handled correctly
  • ✅ Requests without explicit Host headers get the correct default

Verification

# Run the security test
cargo test --test weak_integration test_host_header_security
# Run all tests
cargo test

All tests pass and the code meets quality standards (clippy, formatting).

Fixes#57

🤖 Generated with Claude Code

ammarioand others added 4 commits September 21, 2025 11:12
This commit fixes a security vulnerability where an attacker could bypass
proxy restrictions by sending requests with mismatched Host headers.
The vulnerability allowed sending a request to one domain (e.g., api.anthropic.com)
while setting the Host header to another domain (e.g., evil.com), which could
cause CDNs like CloudFlare to route the request to the attacker's server.
Changes:
- Modified prepare_upstream_request() to ensure Host header always matches URI authority
- Added comprehensive test coverage in weak_integration.rs
- Validates both HTTP and HTTPS requests
This prevents data exfiltration and unauthorized access to protected domains.
Fixes#57
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Simplified the test to clearly demonstrate the vulnerability and fix by:
- Running the same curl command directly (shows evil.com passes through)
- Running it through httpjail (shows it's corrected to httpbin.org)
This makes it clearer that httpjail prevents the Host header bypass
attack that would otherwise be possible.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Added a TODO note documenting future improvement to use the type system
to ensure all request information passed to upstream has been validated
by the RuleEngine. This would provide compile-time guarantees that
security checks cannot be bypassed.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
@ammario
ammario marked this pull request as ready for review September 21, 2025 16:38

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadtests/weak_integration.rs
@ammario
ammario merged commit 664cd1a into mainSep 21, 2025
6 checks passed
@ammario
ammario deleted the url-security branch September 21, 2025 17:09
@ammario

Copy link
Copy Markdown
MemberAuthor

Created issue #59 to track the TODO for using the type system to prevent request validation bypasses. This would make security vulnerabilities like the Host header bypass impossible at compile time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Full proxy bypass on any CloudFlare (or other proxy service) requests

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent Host header bypass vulnerability by ammario · Pull Request #58 · coder/httpjail · GitHub
Skip to content

fix: prevent Host header bypass vulnerability - #58

Merged
ammario merged 4 commits into
mainfrom
url-security
Sep 21, 2025
Merged

fix: prevent Host header bypass vulnerability#58
ammario merged 4 commits into
mainfrom
url-security

Conversation

@ammario

Copy link
Copy Markdown
Member

Summary

This PR fixes a security vulnerability where an attacker could bypass proxy restrictions by sending requests with mismatched Host headers, as described in #57.

The Vulnerability

The issue allowed sending a request to one domain (e.g., api.anthropic.com) while setting the Host header to another domain (e.g., evil.com). This could cause CDNs like CloudFlare to route the request to the attacker's server instead of the intended destination, potentially enabling:

  • Data exfiltration from CloudFlare-protected sites
  • Bypassing proxy restrictions for protected domains

The Fix

Modified prepare_upstream_request() in src/proxy.rs to ensure the Host header always matches the URI authority. The fix:

  1. Extracts the authority (domain:port) from the target URI
  2. Overwrites any existing Host header with the correct value
  3. Applies to both HTTP and HTTPS requests

Testing

Added comprehensive test coverage in tests/weak_integration.rs:

  • ✅ HTTP requests with mismatched Host headers are corrected
  • ✅ HTTPS requests with mismatched Host headers are corrected
  • ✅ Legitimate matching Host headers work normally
  • ✅ Host headers with port numbers are handled correctly
  • ✅ Requests without explicit Host headers get the correct default

Verification

# Run the security test
cargo test --test weak_integration test_host_header_security
# Run all tests
cargo test

All tests pass and the code meets quality standards (clippy, formatting).

Fixes#57

🤖 Generated with Claude Code

ammarioand others added 4 commits September 21, 2025 11:12
This commit fixes a security vulnerability where an attacker could bypass
proxy restrictions by sending requests with mismatched Host headers.
The vulnerability allowed sending a request to one domain (e.g., api.anthropic.com)
while setting the Host header to another domain (e.g., evil.com), which could
cause CDNs like CloudFlare to route the request to the attacker's server.
Changes:
- Modified prepare_upstream_request() to ensure Host header always matches URI authority
- Added comprehensive test coverage in weak_integration.rs
- Validates both HTTP and HTTPS requests
This prevents data exfiltration and unauthorized access to protected domains.
Fixes#57
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Simplified the test to clearly demonstrate the vulnerability and fix by:
- Running the same curl command directly (shows evil.com passes through)
- Running it through httpjail (shows it's corrected to httpbin.org)
This makes it clearer that httpjail prevents the Host header bypass
attack that would otherwise be possible.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Added a TODO note documenting future improvement to use the type system
to ensure all request information passed to upstream has been validated
by the RuleEngine. This would provide compile-time guarantees that
security checks cannot be bypassed.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
@ammario
ammario marked this pull request as ready for review September 21, 2025 16:38

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadtests/weak_integration.rs
@ammario
ammario merged commit 664cd1a into mainSep 21, 2025
6 checks passed
@ammario
ammario deleted the url-security branch September 21, 2025 17:09
@ammario

Copy link
Copy Markdown
MemberAuthor

Created issue #59 to track the TODO for using the type system to prevent request validation bypasses. This would make security vulnerabilities like the Host header bypass impossible at compile time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Full proxy bypass on any CloudFlare (or other proxy service) requests

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent Host header bypass vulnerability by ammario · Pull Request #58 · coder/httpjail · GitHub
Skip to content

fix: prevent Host header bypass vulnerability - #58

Merged
ammario merged 4 commits into
mainfrom
url-security
Sep 21, 2025
Merged

fix: prevent Host header bypass vulnerability#58
ammario merged 4 commits into
mainfrom
url-security

Conversation

@ammario

Copy link
Copy Markdown
Member

Summary

This PR fixes a security vulnerability where an attacker could bypass proxy restrictions by sending requests with mismatched Host headers, as described in #57.

The Vulnerability

The issue allowed sending a request to one domain (e.g., api.anthropic.com) while setting the Host header to another domain (e.g., evil.com). This could cause CDNs like CloudFlare to route the request to the attacker's server instead of the intended destination, potentially enabling:

  • Data exfiltration from CloudFlare-protected sites
  • Bypassing proxy restrictions for protected domains

The Fix

Modified prepare_upstream_request() in src/proxy.rs to ensure the Host header always matches the URI authority. The fix:

  1. Extracts the authority (domain:port) from the target URI
  2. Overwrites any existing Host header with the correct value
  3. Applies to both HTTP and HTTPS requests

Testing

Added comprehensive test coverage in tests/weak_integration.rs:

  • ✅ HTTP requests with mismatched Host headers are corrected
  • ✅ HTTPS requests with mismatched Host headers are corrected
  • ✅ Legitimate matching Host headers work normally
  • ✅ Host headers with port numbers are handled correctly
  • ✅ Requests without explicit Host headers get the correct default

Verification

# Run the security test
cargo test --test weak_integration test_host_header_security
# Run all tests
cargo test

All tests pass and the code meets quality standards (clippy, formatting).

Fixes#57

🤖 Generated with Claude Code

ammarioand others added 4 commits September 21, 2025 11:12
This commit fixes a security vulnerability where an attacker could bypass
proxy restrictions by sending requests with mismatched Host headers.
The vulnerability allowed sending a request to one domain (e.g., api.anthropic.com)
while setting the Host header to another domain (e.g., evil.com), which could
cause CDNs like CloudFlare to route the request to the attacker's server.
Changes:
- Modified prepare_upstream_request() to ensure Host header always matches URI authority
- Added comprehensive test coverage in weak_integration.rs
- Validates both HTTP and HTTPS requests
This prevents data exfiltration and unauthorized access to protected domains.
Fixes#57
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Simplified the test to clearly demonstrate the vulnerability and fix by:
- Running the same curl command directly (shows evil.com passes through)
- Running it through httpjail (shows it's corrected to httpbin.org)
This makes it clearer that httpjail prevents the Host header bypass
attack that would otherwise be possible.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Added a TODO note documenting future improvement to use the type system
to ensure all request information passed to upstream has been validated
by the RuleEngine. This would provide compile-time guarantees that
security checks cannot be bypassed.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
@ammario
ammario marked this pull request as ready for review September 21, 2025 16:38

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadtests/weak_integration.rs
@ammario
ammario merged commit 664cd1a into mainSep 21, 2025
6 checks passed
@ammario
ammario deleted the url-security branch September 21, 2025 17:09
@ammario

Copy link
Copy Markdown
MemberAuthor

Created issue #59 to track the TODO for using the type system to prevent request validation bypasses. This would make security vulnerabilities like the Host header bypass impossible at compile time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Full proxy bypass on any CloudFlare (or other proxy service) requests

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix: prevent Host header bypass vulnerability by ammario · Pull Request #58 · coder/httpjail · GitHub
Skip to content

fix: prevent Host header bypass vulnerability - #58

Merged
ammario merged 4 commits into
mainfrom
url-security
Sep 21, 2025
Merged

fix: prevent Host header bypass vulnerability#58
ammario merged 4 commits into
mainfrom
url-security

Conversation

@ammario

Copy link
Copy Markdown
Member

Summary

This PR fixes a security vulnerability where an attacker could bypass proxy restrictions by sending requests with mismatched Host headers, as described in #57.

The Vulnerability

The issue allowed sending a request to one domain (e.g., api.anthropic.com) while setting the Host header to another domain (e.g., evil.com). This could cause CDNs like CloudFlare to route the request to the attacker's server instead of the intended destination, potentially enabling:

  • Data exfiltration from CloudFlare-protected sites
  • Bypassing proxy restrictions for protected domains

The Fix

Modified prepare_upstream_request() in src/proxy.rs to ensure the Host header always matches the URI authority. The fix:

  1. Extracts the authority (domain:port) from the target URI
  2. Overwrites any existing Host header with the correct value
  3. Applies to both HTTP and HTTPS requests

Testing

Added comprehensive test coverage in tests/weak_integration.rs:

  • ✅ HTTP requests with mismatched Host headers are corrected
  • ✅ HTTPS requests with mismatched Host headers are corrected
  • ✅ Legitimate matching Host headers work normally
  • ✅ Host headers with port numbers are handled correctly
  • ✅ Requests without explicit Host headers get the correct default

Verification

# Run the security test
cargo test --test weak_integration test_host_header_security
# Run all tests
cargo test

All tests pass and the code meets quality standards (clippy, formatting).

Fixes#57

🤖 Generated with Claude Code

ammarioand others added 4 commits September 21, 2025 11:12
This commit fixes a security vulnerability where an attacker could bypass
proxy restrictions by sending requests with mismatched Host headers.
The vulnerability allowed sending a request to one domain (e.g., api.anthropic.com)
while setting the Host header to another domain (e.g., evil.com), which could
cause CDNs like CloudFlare to route the request to the attacker's server.
Changes:
- Modified prepare_upstream_request() to ensure Host header always matches URI authority
- Added comprehensive test coverage in weak_integration.rs
- Validates both HTTP and HTTPS requests
This prevents data exfiltration and unauthorized access to protected domains.
Fixes#57
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Simplified the test to clearly demonstrate the vulnerability and fix by:
- Running the same curl command directly (shows evil.com passes through)
- Running it through httpjail (shows it's corrected to httpbin.org)
This makes it clearer that httpjail prevents the Host header bypass
attack that would otherwise be possible.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Added a TODO note documenting future improvement to use the type system
to ensure all request information passed to upstream has been validated
by the RuleEngine. This would provide compile-time guarantees that
security checks cannot be bypassed.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
@ammario
ammario marked this pull request as ready for review September 21, 2025 16:38

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadtests/weak_integration.rs
@ammario
ammario merged commit 664cd1a into mainSep 21, 2025
6 checks passed
@ammario
ammario deleted the url-security branch September 21, 2025 17:09
@ammario

Copy link
Copy Markdown
MemberAuthor

Created issue #59 to track the TODO for using the type system to prevent request validation bypasses. This would make security vulnerabilities like the Host header bypass impossible at compile time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Full proxy bypass on any CloudFlare (or other proxy service) requests

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent Host header bypass vulnerability by ammario · Pull Request #58 · coder/httpjail · GitHub
Skip to content

fix: prevent Host header bypass vulnerability - #58

Merged
ammario merged 4 commits into
mainfrom
url-security
Sep 21, 2025
Merged

fix: prevent Host header bypass vulnerability#58
ammario merged 4 commits into
mainfrom
url-security

Conversation

@ammario

Copy link
Copy Markdown
Member

Summary

This PR fixes a security vulnerability where an attacker could bypass proxy restrictions by sending requests with mismatched Host headers, as described in #57.

The Vulnerability

The issue allowed sending a request to one domain (e.g., api.anthropic.com) while setting the Host header to another domain (e.g., evil.com). This could cause CDNs like CloudFlare to route the request to the attacker's server instead of the intended destination, potentially enabling:

  • Data exfiltration from CloudFlare-protected sites
  • Bypassing proxy restrictions for protected domains

The Fix

Modified prepare_upstream_request() in src/proxy.rs to ensure the Host header always matches the URI authority. The fix:

  1. Extracts the authority (domain:port) from the target URI
  2. Overwrites any existing Host header with the correct value
  3. Applies to both HTTP and HTTPS requests

Testing

Added comprehensive test coverage in tests/weak_integration.rs:

  • ✅ HTTP requests with mismatched Host headers are corrected
  • ✅ HTTPS requests with mismatched Host headers are corrected
  • ✅ Legitimate matching Host headers work normally
  • ✅ Host headers with port numbers are handled correctly
  • ✅ Requests without explicit Host headers get the correct default

Verification

# Run the security test
cargo test --test weak_integration test_host_header_security
# Run all tests
cargo test

All tests pass and the code meets quality standards (clippy, formatting).

Fixes#57

🤖 Generated with Claude Code

ammarioand others added 4 commits September 21, 2025 11:12
This commit fixes a security vulnerability where an attacker could bypass
proxy restrictions by sending requests with mismatched Host headers.
The vulnerability allowed sending a request to one domain (e.g., api.anthropic.com)
while setting the Host header to another domain (e.g., evil.com), which could
cause CDNs like CloudFlare to route the request to the attacker's server.
Changes:
- Modified prepare_upstream_request() to ensure Host header always matches URI authority
- Added comprehensive test coverage in weak_integration.rs
- Validates both HTTP and HTTPS requests
This prevents data exfiltration and unauthorized access to protected domains.
Fixes#57
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Simplified the test to clearly demonstrate the vulnerability and fix by:
- Running the same curl command directly (shows evil.com passes through)
- Running it through httpjail (shows it's corrected to httpbin.org)
This makes it clearer that httpjail prevents the Host header bypass
attack that would otherwise be possible.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Added a TODO note documenting future improvement to use the type system
to ensure all request information passed to upstream has been validated
by the RuleEngine. This would provide compile-time guarantees that
security checks cannot be bypassed.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
@ammario
ammario marked this pull request as ready for review September 21, 2025 16:38

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadtests/weak_integration.rs
@ammario
ammario merged commit 664cd1a into mainSep 21, 2025
6 checks passed
@ammario
ammario deleted the url-security branch September 21, 2025 17:09
@ammario

Copy link
Copy Markdown
MemberAuthor

Created issue #59 to track the TODO for using the type system to prevent request validation bypasses. This would make security vulnerabilities like the Host header bypass impossible at compile time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Full proxy bypass on any CloudFlare (or other proxy service) requests

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent Host header bypass vulnerability by ammario · Pull Request #58 · coder/httpjail · GitHub
Skip to content

fix: prevent Host header bypass vulnerability - #58

Merged
ammario merged 4 commits into
mainfrom
url-security
Sep 21, 2025
Merged

fix: prevent Host header bypass vulnerability#58
ammario merged 4 commits into
mainfrom
url-security

Conversation

@ammario

Copy link
Copy Markdown
Member

Summary

This PR fixes a security vulnerability where an attacker could bypass proxy restrictions by sending requests with mismatched Host headers, as described in #57.

The Vulnerability

The issue allowed sending a request to one domain (e.g., api.anthropic.com) while setting the Host header to another domain (e.g., evil.com). This could cause CDNs like CloudFlare to route the request to the attacker's server instead of the intended destination, potentially enabling:

  • Data exfiltration from CloudFlare-protected sites
  • Bypassing proxy restrictions for protected domains

The Fix

Modified prepare_upstream_request() in src/proxy.rs to ensure the Host header always matches the URI authority. The fix:

  1. Extracts the authority (domain:port) from the target URI
  2. Overwrites any existing Host header with the correct value
  3. Applies to both HTTP and HTTPS requests

Testing

Added comprehensive test coverage in tests/weak_integration.rs:

  • ✅ HTTP requests with mismatched Host headers are corrected
  • ✅ HTTPS requests with mismatched Host headers are corrected
  • ✅ Legitimate matching Host headers work normally
  • ✅ Host headers with port numbers are handled correctly
  • ✅ Requests without explicit Host headers get the correct default

Verification

# Run the security test
cargo test --test weak_integration test_host_header_security
# Run all tests
cargo test

All tests pass and the code meets quality standards (clippy, formatting).

Fixes#57

🤖 Generated with Claude Code

ammarioand others added 4 commits September 21, 2025 11:12
This commit fixes a security vulnerability where an attacker could bypass
proxy restrictions by sending requests with mismatched Host headers.
The vulnerability allowed sending a request to one domain (e.g., api.anthropic.com)
while setting the Host header to another domain (e.g., evil.com), which could
cause CDNs like CloudFlare to route the request to the attacker's server.
Changes:
- Modified prepare_upstream_request() to ensure Host header always matches URI authority
- Added comprehensive test coverage in weak_integration.rs
- Validates both HTTP and HTTPS requests
This prevents data exfiltration and unauthorized access to protected domains.
Fixes#57
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Simplified the test to clearly demonstrate the vulnerability and fix by:
- Running the same curl command directly (shows evil.com passes through)
- Running it through httpjail (shows it's corrected to httpbin.org)
This makes it clearer that httpjail prevents the Host header bypass
attack that would otherwise be possible.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Added a TODO note documenting future improvement to use the type system
to ensure all request information passed to upstream has been validated
by the RuleEngine. This would provide compile-time guarantees that
security checks cannot be bypassed.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
@ammario
ammario marked this pull request as ready for review September 21, 2025 16:38

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadtests/weak_integration.rs
@ammario
ammario merged commit 664cd1a into mainSep 21, 2025
6 checks passed
@ammario
ammario deleted the url-security branch September 21, 2025 17:09
@ammario

Copy link
Copy Markdown
MemberAuthor

Created issue #59 to track the TODO for using the type system to prevent request validation bypasses. This would make security vulnerabilities like the Host header bypass impossible at compile time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Full proxy bypass on any CloudFlare (or other proxy service) requests

1 participant

@ammario
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix: prevent Host header bypass vulnerability by ammario · Pull Request #58 · coder/httpjail · GitHub
Skip to content

fix: prevent Host header bypass vulnerability - #58

Merged
ammario merged 4 commits into
mainfrom
url-security
Sep 21, 2025
Merged

fix: prevent Host header bypass vulnerability#58
ammario merged 4 commits into
mainfrom
url-security

Conversation

@ammario

Copy link
Copy Markdown
Member

Summary

This PR fixes a security vulnerability where an attacker could bypass proxy restrictions by sending requests with mismatched Host headers, as described in #57.

The Vulnerability

The issue allowed sending a request to one domain (e.g., api.anthropic.com) while setting the Host header to another domain (e.g., evil.com). This could cause CDNs like CloudFlare to route the request to the attacker's server instead of the intended destination, potentially enabling:

  • Data exfiltration from CloudFlare-protected sites
  • Bypassing proxy restrictions for protected domains

The Fix

Modified prepare_upstream_request() in src/proxy.rs to ensure the Host header always matches the URI authority. The fix:

  1. Extracts the authority (domain:port) from the target URI
  2. Overwrites any existing Host header with the correct value
  3. Applies to both HTTP and HTTPS requests

Testing

Added comprehensive test coverage in tests/weak_integration.rs:

  • ✅ HTTP requests with mismatched Host headers are corrected
  • ✅ HTTPS requests with mismatched Host headers are corrected
  • ✅ Legitimate matching Host headers work normally
  • ✅ Host headers with port numbers are handled correctly
  • ✅ Requests without explicit Host headers get the correct default

Verification

# Run the security test
cargo test --test weak_integration test_host_header_security
# Run all tests
cargo test

All tests pass and the code meets quality standards (clippy, formatting).

Fixes#57

🤖 Generated with Claude Code

ammarioand others added 4 commits September 21, 2025 11:12
This commit fixes a security vulnerability where an attacker could bypass
proxy restrictions by sending requests with mismatched Host headers.
The vulnerability allowed sending a request to one domain (e.g., api.anthropic.com)
while setting the Host header to another domain (e.g., evil.com), which could
cause CDNs like CloudFlare to route the request to the attacker's server.
Changes:
- Modified prepare_upstream_request() to ensure Host header always matches URI authority
- Added comprehensive test coverage in weak_integration.rs
- Validates both HTTP and HTTPS requests
This prevents data exfiltration and unauthorized access to protected domains.
Fixes#57
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Simplified the test to clearly demonstrate the vulnerability and fix by:
- Running the same curl command directly (shows evil.com passes through)
- Running it through httpjail (shows it's corrected to httpbin.org)
This makes it clearer that httpjail prevents the Host header bypass
attack that would otherwise be possible.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
Added a TODO note documenting future improvement to use the type system
to ensure all request information passed to upstream has been validated
by the RuleEngine. This would provide compile-time guarantees that
security checks cannot be bypassed.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
@ammario
ammario marked this pull request as ready for review September 21, 2025 16:38

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex Review: Here are some suggestions.

Reply with @codex fix comments to fix any unresolved comments.

About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you open a pull request for review, mark a draft as ready, or comment "@codex review". If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex fix this CI failure" or "@codex address that feedback".

Comment threadtests/weak_integration.rs
@ammario
ammario merged commit 664cd1a into mainSep 21, 2025
6 checks passed
@ammario
ammario deleted the url-security branch September 21, 2025 17:09
@ammario

Copy link
Copy Markdown
MemberAuthor

Created issue #59 to track the TODO for using the type system to prevent request validation bypasses. This would make security vulnerabilities like the Host header bypass impossible at compile time.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Full proxy bypass on any CloudFlare (or other proxy service) requests

1 participant

@ammario