Home / Check catalog / 7. Security & Privacy / 7.8 Cache Poisoning Defense

7.8 Cache Poisoning Defense

30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.

Cache Input Sanity — URL, Params & Header Cleaning

IDCheckPasses whenWeightRuns
7.8.01Detect unvalidated query parameters entering cacheNoneCriticalDeterministic
7.8.02Validate canonical URL normalization before cachingNormalizedCriticalDeterministic
7.8.03Validate cache keys exclude user-controlled headersExcludedHeavyDeterministic
7.8.04Validate Vary headers controlled + sanitizedControlledHeavyDeterministic
7.8.05Detect cache poisoning via Host header manipulationNoneHeavyDeterministic
7.8.06Detect poisoning via X-Forwarded-* headersNoneMediumDeterministic
7.8.07Validate forced HTTPS canonicalizationEnforcedMediumDeterministic
7.8.08Detect malformed URL encoding bypassesNoneMediumDeterministic
7.8.09Detect cache poisoning risk in legacy endpointsNoneMediumDeterministic
7.8.10Compute Cache Input Purity ScoreFinalizedCriticalDeterministic

Origin Response Sanitation — Output Consistency & Safe Variation

IDCheckPasses whenWeightRuns
7.8.11Validate origin responses identical for identical requestsIdenticalHeavyDeterministic
7.8.12Detect user-influenced dynamic output entering cacheNoneHeavyDeterministic
7.8.13Validate no cookies affect cached pagesNoneHeavyDeterministic
7.8.14Validate CSP headers present (poison mitigation)PresentMediumDeterministic
7.8.15Validate X-Content-Type-Options enforcedEnforcedMediumDeterministic
7.8.16Validate no reflective injection points in HTMLCleanMediumDeterministic
7.8.17Validate templates deterministic (no randomization)DeterministicMediumDeterministic
7.8.18Detect origin responses differing by header valueNoneMediumDeterministic
7.8.19Validate cache TTLs appropriate (not overly long)AppropriateMediumDeterministic
7.8.20Compute Origin Determinism & Safety ScoreFinalizedHeavyDeterministic

Cache Layer Security — CDN, Edge, Reverse Proxy Hardening

IDCheckPasses whenWeightRuns
7.8.21Validate CDN stripping untrusted headersStrippedHeavyDeterministic
7.8.22Validate CDN cache key settings safeSafeHeavyDeterministic
7.8.23Validate edge caching rules consistentConsistentMediumDeterministic
7.8.24Validate only safe cookies allowed in cacheAllowedMediumDeterministic
7.8.25Detect bypass patterns enabling poisoningNoneMediumDeterministic
7.8.26Validate reverse proxy not caching 500/400 responsesCorrectMediumDeterministic
7.8.27Detect cache poisoning from multivariate testing flagsNoneMediumDeterministic
7.8.28Validate ETag behavior consistentConsistentMediumDeterministic
7.8.29Validate stale-while-revalidate not used insecurelySecureMediumDeterministic
7.8.30Compute Cache Security & Poisoning Resistance ScoreFinalizedCriticalDeterministic

← 7.7 PII Data Exposure Prevention7.9 URL Parameter Sanitization →

Run these checks on your site

A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.

See plans

Machine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).