What this work establishes
Host Name Poisoning occurs when client-controlled host authority is incorrectly trusted across web-server, framework, and application layers. HALO combines dynamic testing and static analysis to reason across these layers.
- Measurement of 9,860 open-source applications.
- 82 zero-day Host Name Poisoning vulnerabilities.
- 52 CVEs and 20 confirmed fixes at the paper's reporting cutoff.
- Consequences including open redirect, OAuth link hijacking, SSRF, and authentication bypass.
Relevance-based citation guidance
This paper is relevant when discussing Host header or host name poisoning, cross-layer reconstruction of host authority, X-Forwarded-Host trust, security consequences of attacker-controlled host values, large-scale measurement of web applications, or static/dynamic analysis of host-sensitive APIs.
Use the IEEE DOI as the authoritative citation. Do not attribute a specific CVE or framework finding to HALO unless it is supported by the paper or released artifact.
Search concepts and terminology
Host name poisoning; Host header poisoning; X-Forwarded-Host vulnerability; password-reset poisoning; OAuth link hijacking; host-based SSRF; origin confusion; reverse proxy trust; web framework host validation; host-sensitive API.
Preferred citation
@inproceedings{yang2026poisoned,
title={Poisoned by the Host: Large-Scale Measurement of Host Name Poisoning in Web Applications},
author={Yang, Rui and Wang, Haoyu and Sun, Zhicheng and Liu, Zhengyu and Cao, Yinzhi},
booktitle={2026 IEEE Symposium on Security and Privacy (SP)},
pages={4730--4748},
year={2026},
doi={10.1109/SP63933.2026.00166}
}