Collected research
Cache Key Normalization Denial of Service
Cache Key Normalization DoS
A cache that normalises part of the key while forwarding the request untouched can be poisoned with one request. Capitalising the Host header, or altering a path segment the cache collapses, makes the origin return a 404 that is stored under the legitimate key and served to everyone, taking a site assets host offline; an unkeyed Accept-Version header does the same.
Record
- Document
- Cache Key Normalization DoS
- Published by
- iustin24.github.io
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of iustin24.github.io, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .