Collected research
XSS using dirty Content Type in cloud era
Examines how HTTP Content-Type is parsed differently by RFC 9110 and the WHATWG Fetch standard, which splits the field on commas and takes the last media type, so values such as image/png,text/html defeat prefix, suffix, regex and substring allowlists. Cloud object storage makes this reachable: all three upload paths let the client set the stored Content-Type metadata, which the browser then honours. Two carrierwave advisories are traced, and exact-match validation is recommended.
Record
- Researcher
- Norihide Saito and Eiji Mori
- Published by
- Speaker Deck
- Date
- Format
- Slides
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Norihide Saito and Eiji Mori, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .