X-Backend-Server Header Information Leak
- Risk:
Low
- Type:
- Passive
- CWE:
- CWE-200
- Summary
The server is leaking information pertaining to backend systems (such as hostnames or IP addresses). Armed with this information an attacker may be able to attack other systems or more directly/efficiently attack those systems.
- Solution
Ensure that your web server, application server, load balancer, etc. is configured to suppress X-Backend-Server headers.
Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks
Hackers Exploit Milesight Routers to Send Phishing SMS to European Users
Severe Framelink Figma MCP Vulnerability Lets Hackers Execute Code Remotely
Microsoft: Hackers target universities in “payroll pirate” attacks
Oracle silently fixes zero-day exploit leaked by ShinyHunters
Co-op says it lost $107 million after Scattered Spider attack
FBI takes down BreachForums portal used for Salesforce extortion
Another remotely exploitable Oracle EBS vulnerability requires your attention (CVE-2025-61884)
New Android Pixnapping attack steals MFA codes pixel-by-pixel
CVE-2025-54253 Adobe Experience Manager Forms Code Execution Vulnerability
CVE-2016-7836 SKYSEA Client View Improper Authentication Vulnerability
CVE-2025-6264 Rapid7 Velociraptor Incorrect Default Permissions Vulnerability
CVE-2025-59230 Microsoft Windows Improper Access Control Vulnerability
CVE-2025-24990 Microsoft Windows Untrusted Pointer Dereference Vulnerability
CVE-2025-47827 IGEL OS Use of a Key Past its Expiration Date Vulnerability
CVE-2025-27915 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
CVE-2025-61882 Oracle E-Business Suite Unspecified Vulnerability
CVE-2010-3765 Mozilla Multiple Products Remote Code Execution Vulnerability
InformationalObsolete Content Security Policy (CSP) Header Found
HighPath Traversal
InformationalInformation Disclosure - Sensitive Information in URL
InformationalSec-Fetch-Mode Header Has an Invalid Value
InformationalStorable and Cacheable Content
LowCSP: Notices
Free online web security scanner