Skip to content

Archive

Web Security

130 articles
Cybersecurity 17 Sep 2026 8 min read

CSP Strict Dynamic Moves Script Trust From Host Lists to Nonce-Bearing Roots

CSP Strict Dynamic Moves Script Trust From Host Lists to Nonce-Bearing Roots A production page can have a restrictive script-src policy and still depend on a bootstrap script that creates additional script elements at runtime. A host allowlist handles that architecture by naming every permitted script origin. The list then becomes coupled to deployment topology: moving a dependency to another host can require a policy change, while admitting a broad host can authorize more executable content than the application intended.

Cybersecurity 16 Sep 2026 7 min read

WebSocket Origin Checks Keep Browser Sessions Inside an Explicit Trust Boundary

A user can be signed in to a WebSocket-backed application while browsing an unrelated site in another tab. JavaScript on that unrelated site can attempt a WebSocket connection to the application’s endpoint. If the browser attaches credentials applicable to the handshake and the server upgrades the connection without checking the initiating origin, the new message channel can inherit authenticated authority that the page itself was never meant to receive. This boundary differs from ordinary cross-origin fetch() handling. WebSocket establishes its own protocol channel through an HTTP opening handshake, and the server has to decide whether the browser origin named in that handshake is permitted to create the channel. CORS response policy is not a substitute for that decision.

Cybersecurity 16 Sep 2026 9 min read

WebAuthn RP IDs Bind Credentials to Domain Scope, Not a Single Origin

WebAuthn RP IDs Bind Credentials to Domain Scope, Not a Single Origin An authentication service at https://login.example.com can create a WebAuthn credential scoped to example.com rather than only to its own host. That choice permits eligible sibling origins under the same domain to request use of the credential, yet an assertion still carries the calling origin for server-side validation. WebAuthn deliberately separates these two identities. The split solves a practical architecture problem: one relying party can operate across multiple web origins without issuing an unrelated credential for every host. It also creates a security boundary that is easy to flatten incorrectly. The RP ID controls credential scope at the client and authenticator layers; the origin identifies the web context that initiated a ceremony. Treating either value as a substitute for the other can expand authentication authority beyond the intended deployment.

Cybersecurity 16 Sep 2026 7 min read

Fetch Metadata Lets Servers Reject Cross-Site Request Contexts

Fetch Metadata Lets Servers Reject Cross-Site Request Contexts An authenticated endpoint can receive a syntactically valid request carrying ambient credentials even when the navigation or resource load began on another site. Cookies alone do not tell the server what browser context produced the request. Fetch Metadata adds request headers that expose selected context already known to the user agent, giving the server another signal before it accepts a state-changing operation or serves a sensitive resource.

Cybersecurity 16 Sep 2026 10 min read

DNS Rebinding Turns Name Resolution Into a Moving Network Boundary

A browser loads script from an attacker-controlled hostname while that name resolves to a public server. Seconds later, another lookup for the same hostname returns a private address such as an RFC 1918 destination. The browser still sees the same scheme, host, and port in the URL, yet a subsequent connection can terminate at a different machine. That gap between web origin identity and network destination is the basis of DNS rebinding. The same-origin policy primarily reasons about origins expressed through URL components; it does not define an origin by the IP address selected by DNS for each connection. An attacker who controls both a hostname and its DNS answers can exploit that separation when a browser is permitted to resolve the name to a target reachable from the user’s network.

Cybersecurity 16 Sep 2026 9 min read

DNS Rebinding Turns Name Resolution Into a Browser Network Pivot

DNS Rebinding Turns Name Resolution Into a Browser Network Pivot A browser can load active content from a public server, keep the same URL origin, then resolve that origin name to a different IP address later. If the new address reaches a service on a private network, the browser has become a transport path between attacker-controlled code and a target that was never intended to accept requests from the public Internet.

Cybersecurity 16 Sep 2026 9 min read

CSP Strict-Dynamic Shifts Script Trust From Hosts to Execution Lineage

CSP Strict-Dynamic Shifts Script Trust From Hosts to Execution Lineage A page can carry a restrictive script host list and still face a difficult deployment choice when its trusted bootstrap code loads dependencies at runtime. Adding every current script host to script-src keeps policy tied to network locations that can change. Adding 'strict-dynamic' takes a different route: in supporting browsers, trust attached to a nonce-bearing or hash-authorized root script can propagate to scripts that root code inserts dynamically.

Cybersecurity 16 Sep 2026 8 min read

CORS Preflight Caching Extends Cross-Origin Policy Decisions

CORS Preflight Caching Extends Cross-Origin Policy Decisions An API operator can remove a cross-origin method from its CORS configuration and still see browsers issue that method without a fresh OPTIONS exchange. The browser may already hold a valid preflight cache entry authorizing the request shape. Until that entry expires or is discarded, the earlier policy decision can continue to suppress a new preflight. This behavior does not make CORS authorization permanent, and it does not bypass the CORS check on the actual response. It does create an operational interval in which a server-side policy change and browser preflight behavior are not synchronized. Access-Control-Max-Age therefore affects more than request volume: it influences the lifetime of a cached permission decision inside the user agent.

Cybersecurity 16 Sep 2026 8 min read

Cache Keys Define the Security Boundary of Shared HTTP Responses

Cache Keys Define the Security Boundary of Shared HTTP Responses A reverse proxy receives two requests for the same URL. One carries a header that changes the origin response; the other does not. If the proxy stores the first response under a key that ignores that header, the second request can receive content generated from state it never supplied. The cache is operating correctly according to its key, yet the key has merged two requests that the application treats as distinct.

Cybersecurity 15 Sep 2026 7 min read

Subresource Integrity Pins External Assets to Expected Bytes

Subresource Integrity Pins External Assets to Expected Bytes A web page can keep all of its application code under careful review and still execute JavaScript delivered from infrastructure outside its control. Analytics libraries, UI frameworks, payment components, and other dependencies are often fetched from a content delivery network. If that remote response changes, the browser normally has no basis for deciding whether the new bytes are an approved release or an unexpected substitution.

Cybersecurity 15 Sep 2026 8 min read

Strict CSP Moves Script Trust From Hostnames to Authorized Roots

A script policy built around a long list of approved hosts can look restrictive while still granting more authority than the application intends. If any approved origin can serve attacker-influenced JavaScript, or exposes a path that behaves as a script gadget, the hostname boundary may admit code that the page never meant to execute. A strict Content Security Policy changes the basis of that decision. Instead of treating network location as the primary proof that a script is acceptable, the page marks specific root scripts with a fresh nonce or a matching cryptographic hash. With 'strict-dynamic', trust can then follow script-loading relationships created by those authorized roots.

Cybersecurity 15 Sep 2026 5 min read

SameSite Cookies Move CSRF Control Into Request Context

A browser can send an authenticated request that the account holder never intended to initiate. The target site may receive a valid session cookie, see a legitimate account, and process a state change even though the request originated from another site. The credential is ambient: browser attachment, not explicit application code, supplies it. The SameSite cookie attribute changes that attachment decision. Rather than asking the server to distinguish hostile requests after every cookie arrives, it gives the user agent policy for deciding whether a cookie accompanies requests in cross-site contexts. That moves part of the CSRF boundary into browser request processing, but only for cookies covered by the attribute and only according to the site’s relationship and request context defined by browser policy.

Cybersecurity 15 Sep 2026 7 min read

HTTP Request Smuggling Starts at Message-Boundary Disagreement

HTTP Request Smuggling Starts at Message-Boundary Disagreement A reverse proxy can validate an HTTP request, forward it to an application server, and still leave both systems with different views of where that request ends. The bytes do not need to change in transit. The security failure appears when two parsers assign different boundaries to the same stream. That disagreement is the core of HTTP request smuggling. One component consumes a prefix as a complete request while another treats additional bytes as part of that request, or as the beginning of a following one. On a reused backend connection, the leftover bytes can alter the interpretation of traffic that arrives later.

Cybersecurity 15 Sep 2026 6 min read

HSTS Turns HTTPS Preference Into Browser Policy

HSTS Turns HTTPS Preference Into Browser Policy An HTTPS site can configure perfect TLS and still expose a weaker first contact. If a person types a bare hostname, follows an old http:// bookmark, or opens an insecure link, the browser may send an HTTP request before the server redirects it to HTTPS. An active network attacker gets an opportunity before the protected connection exists. HTTP Strict Transport Security, or HSTS, moves that redirect decision into the browser. After a browser receives a valid HSTS policy over HTTPS, it records that the host must be contacted securely for the policy lifetime. Later HTTP navigation to that host is upgraded locally rather than sent across the network as cleartext HTTP.

Cybersecurity 15 Sep 2026 6 min read

HSTS Turns First Contact Into Persistent HTTPS Policy

A site can redirect every plain HTTP request to HTTPS and still expose a gap before that redirect arrives. On an untrusted network, the first cleartext request can be intercepted, altered, or answered by another system before the browser receives the server’s redirect. TLS cannot protect a request that has not entered TLS yet. HTTP Strict Transport Security changes browser behavior after a secure contact. A conforming user agent that receives a valid Strict-Transport-Security field over HTTPS records a policy for the host. During the policy lifetime, later attempts to use HTTP for that host are rewritten to HTTPS internally before an insecure request is sent.

Cybersecurity 15 Sep 2026 6 min read

Fetch Metadata Makes Cross-Site Request Context Visible

Fetch Metadata Makes Cross-Site Request Context Visible A server receiving an authenticated HTTP request often sees valid cookies, a plausible path, and a method that the application accepts. Those facts do not reveal whether the request began inside the application’s own page or was triggered by a document on another site. For endpoints that change state, that missing context has long been central to cross-site request forgery defenses. Fetch Metadata request headers expose part of the context already known to the browser. Headers such as Sec-Fetch-Site, Sec-Fetch-Mode, Sec-Fetch-Dest, and Sec-Fetch-User describe relationships and properties surrounding a request. A server can use those signals to reject request patterns that do not belong to its application architecture.

Cybersecurity 15 Sep 2026 6 min read

DNS Rebinding Turns Hostname Trust Into Network Reach

DNS Rebinding Turns Hostname Trust Into Network Reach A browser tab can keep the same scheme, hostname, and port while the IP address behind that hostname changes. That ordinary property of DNS becomes dangerous when software assumes the address reached by a browser is fixed for the lifetime of an origin. DNS rebinding attacks exploit the gap between two identities. Browser security policy is largely expressed in terms of origins, where a hostname is part of the identity. Network services often reason in terms of addresses and interfaces: loopback, a private subnet, a management VLAN, or another location considered unreachable from the public internet. Rebinding can preserve the browser-visible hostname while steering later connections toward a different network address.

Cybersecurity 15 Sep 2026 5 min read

DNS Rebinding Turns Browser Origin Trust Into a Network Pivot

DNS Rebinding Turns Browser Origin Trust Into a Network Pivot A browser can keep treating a page as belonging to the same web origin even after the hostname behind that origin starts resolving to a different IP address. That separation between origin identity and network destination creates the opening for DNS rebinding. The attacker does not need to convince a local service to initiate an outbound connection. Instead, a page already running in the browser issues requests under an attacker-controlled hostname. If subsequent DNS resolution maps that hostname to a loopback, private, or otherwise locally reachable address, the browser can become a bridge between remote content and a service exposed only to the victim’s network.

Cybersecurity 15 Sep 2026 8 min read

Content Security Policy Makes Script Authority Explicit

Content Security Policy Makes Script Authority Explicit A browser does not distinguish between JavaScript that a development team intended to ship and JavaScript that arrived through an injection flaw. Once script markup becomes part of a document and passes the browser’s normal parsing rules, it can execute with the authority of that origin. Escaping and contextual output encoding remain primary defenses against injection, but a single missed boundary can still turn untrusted text into active code.

Cybersecurity 15 Sep 2026 7 min read

Certificate Transparency Turns Misissuance Into Public Evidence

Certificate Transparency Turns Misissuance Into Public Evidence A certificate authority can validate a request correctly according to its own process and still produce a certificate that a domain operator never expected. The Web PKI cannot make every issuance decision infallible, so Certificate Transparency adds a different property: public TLS certificate issuance can be recorded in logs that independent parties can inspect and audit. That distinction is central to the mechanism. Certificate Transparency does not decide whether an applicant is authorized to control a domain. It does not replace certificate validation, revocation, or DNS CAA policy. Its role is to make issuance observable and to make the log’s own history cryptographically auditable.

Cybersecurity 14 Sep 2026 7 min read

WebAuthn Binds Credentials to a Web Origin

A convincing imitation of a login page can reproduce almost every visible detail of the original site. It can copy the logo, typography, form layout, error messages, and even the sequence of prompts. Password authentication gives that imitation a useful target: a secret that a person can type into the wrong origin and an attacker can relay or reuse elsewhere. WebAuthn changes that property. Its credentials are public-key pairs scoped to a relying party, and authentication produces a signed assertion tied to data supplied by the site and context supplied by the browser. The credential is not a reusable string exposed to the page. That difference moves a large part of phishing resistance from visual recognition into protocol enforcement.

Cybersecurity 14 Sep 2026 6 min read

SameSite Cookies Bound Cross-Site Credential Sending

SameSite Cookies Bound Cross-Site Credential Sending A browser can send an authenticated request that the account holder never intended to make. The application may see a valid session cookie, a normal HTTP method, and a request arriving over TLS. None of those facts proves that the request originated from a page the application trusts. That gap is central to cross-site request forgery. Cookie-based sessions are ambient credentials: once stored, they can be attached by the browser according to cookie rules rather than by deliberate application code at each request. The SameSite attribute changes those rules by restricting cookie attachment in cross-site contexts.

Cybersecurity 14 Sep 2026 6 min read

Rotate Session Identifiers Across Authentication Boundaries

Rotate Session Identifiers Across Authentication Boundaries A login endpoint can validate credentials perfectly and still hand an attacker an authenticated session. The failure appears when the application keeps the same session identifier before and after authentication, allowing an identifier established under anonymous conditions to survive a major increase in authority. That pattern is session fixation. It differs from session theft in an important respect: the attacker does not need to extract a secret identifier from an authenticated browser. Instead, the attacker arranges for a known identifier to become associated with a victim’s authenticated state. Once the victim signs in, possession of that already-known identifier may be enough to access the resulting session.

Cybersecurity 14 Sep 2026 6 min read

HTTP Request Smuggling Exploits Parser Disagreement

HTTP Request Smuggling Exploits Parser Disagreement A reverse proxy and an application server can each parse the same byte stream according to rules that appear reasonable in isolation. Trouble starts when they reach different answers about where one request ends. Bytes treated as the tail of a request by the front end can become the start of another request at the back end, shifting the interpretation of traffic that follows on a reused connection.