FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
When Proxies Become the Attack Vectors in Web Architectures
NewsSecurity

When Proxies Become the Attack Vectors in Web Architectures

via Dev.toNathan Sportsman2w ago

Many modern web applications rely on a flawed assumption: backends can blindly trust security-critical headers from upstream reverse proxies. This assumption breaks down because HTTP RFC flexibility allows different servers to interpret the same header field in fundamentally different ways, creating exploitable gaps that attackers are increasingly targeting. Two recent CVEs I discovered expose this systemic problem and demonstrate why these are not isolated bugs, but symptoms of a much broader architectural flaw. When CVE-2025-48865 in Fabio and CVE-2025-64484 in OAuth2-proxy both enable identical attack patterns across completely different technologies, it reveals that our industry has fundamentally misunderstood where the real security boundaries lie. TL;DR: Two newly discovered CVEs (CVE-2025-48865 in Fabio, CVE-2025-64484 in OAuth2-proxy) expose a systemic vulnerability in how reverse proxies handle header processing. By exploiting hop-by-hop header stripping and underscore-hyphen

Continue reading on Dev.to

Opens in a new tab

Read Full Article
6 views

Related Articles

Morse Code Is a Variable-Length Binary Encoding From 1837
News

Morse Code Is a Variable-Length Binary Encoding From 1837

Dev.to Beginners • 1w ago

The BB-777 is the ultimate in boombox nostalgia
News

The BB-777 is the ultimate in boombox nostalgia

The Verge • 1w ago

Actuarial Tables and the Math Behind Life Expectancy Estimates
News

Actuarial Tables and the Math Behind Life Expectancy Estimates

Dev.to Beginners • 1w ago

Amazon just bought a startup making kid-size humanoid robots
News

Amazon just bought a startup making kid-size humanoid robots

TechCrunch • 1w ago

News

The Fragile Thread

Medium Programming • 1w ago

Discover More Articles