logoalt Hacker News

Bratmon01/04/20261 replyview on HN

> That's not a reason not to consider it a threat vector when implementing, but no more than when implementing any header (that interacts with another)

But the header wouldn't have interacted with another header if we hadn't decided to do this X-prefix nonsense!


Replies

lucideer01/04/2026

It might not have but it's a lot more likely that it would.