Web Hack List

Collected research

XSS using dirty Content Type in cloud era

Examines how HTTP Content-Type is parsed differently by RFC 9110 and the WHATWG Fetch standard, which splits the field on commas and takes the last media type, so values such as image/png,text/html defeat prefix, suffix, regex and substring allowlists. Cloud object storage makes this reachable: all three upload paths let the client set the stored Content-Type metadata, which the browser then honours. Two carrierwave advisories are traced, and exact-match validation is recommended.

Record

Researcher
Norihide Saito and Eiji Mori
Published by
Speaker Deck
Date
Format
Slides
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Norihide Saito and Eiji Mori, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .