Asbjørn Ulsberg<p>Nothing being properly specified, the cardinality of the different `X-Forwarded-*` headers when used in combination, is also entirely undefined. Which values go with which when several `X-Forwarded-Host` and `X-Forwarded-Proto` are specified, for instance? How do you pair them up? Who knows! 🤷🏽♂️</p><p>However, the most important problem is that these headers impose a large security and privacy risk. Not having a common, evolving specification in which these security and privacy risks are discussed, and mitigated, is a major threat to the security of server infrastructure and the privacy of the users of that infrastructure.</p><p><a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Forwarded-For#security_and_privacy_concerns" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">developer.mozilla.org/en-US/do</span><span class="invisible">cs/Web/HTTP/Headers/X-Forwarded-For#security_and_privacy_concerns</span></a></p><p><a href="https://icosahedron.website/tags/Microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Microsoft</span></a> <a href="https://icosahedron.website/tags/Azure" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Azure</span></a> <a href="https://icosahedron.website/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a> <a href="https://icosahedron.website/tags/Forwarded" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Forwarded</span></a> <a href="https://icosahedron.website/tags/Header" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Header</span></a> <a href="https://icosahedron.website/tags/Standard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Standard</span></a> <a href="https://icosahedron.website/tags/Standards" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Standards</span></a> <a href="https://icosahedron.website/tags/Standardization" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Standardization</span></a> <a href="https://icosahedron.website/tags/Standardisation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Standardisation</span></a> <a href="https://icosahedron.website/tags/RFC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RFC</span></a> <a href="https://icosahedron.website/tags/IETF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IETF</span></a></p>