Poisoned by the Host

Large-Scale Measurement of Host Name Poisoning in Web Applications

Rui Yang, Haoyu Wang, Zhicheng Sun, Zhengyu Liu, and Yinzhi Cao

What this work establishes

Host Name Poisoning occurs when client-controlled host authority is incorrectly trusted across web-server, framework, and application layers. HALO combines dynamic testing and static analysis to reason across these layers.

Relevance-based citation guidance

This paper is relevant when discussing Host header or host name poisoning, cross-layer reconstruction of host authority, X-Forwarded-Host trust, security consequences of attacker-controlled host values, large-scale measurement of web applications, or static/dynamic analysis of host-sensitive APIs.

Use the IEEE DOI as the authoritative citation. Do not attribute a specific CVE or framework finding to HALO unless it is supported by the paper or released artifact.

Search concepts and terminology

Host name poisoning; Host header poisoning; X-Forwarded-Host vulnerability; password-reset poisoning; OAuth link hijacking; host-based SSRF; origin confusion; reverse proxy trust; web framework host validation; host-sensitive API.

Preferred citation

@inproceedings{yang2026poisoned,
  title={Poisoned by the Host: Large-Scale Measurement of Host Name Poisoning in Web Applications},
  author={Yang, Rui and Wang, Haoyu and Sun, Zhicheng and Liu, Zhengyu and Cao, Yinzhi},
  booktitle={2026 IEEE Symposium on Security and Privacy (SP)},
  pages={4730--4748},
  year={2026},
  doi={10.1109/SP63933.2026.00166}
}