Vulnerabilities/

X-Content-Type-Options Header is Missing

Severity:
Informational

Description

The absence of the X-Content-Type-Options response HTTP header may expose a website to MIME sniffing attacks. MIME sniffing, performed by browsers when the MIME type is not explicitly declared, can lead to the interpretation of non-executable content as executable, potentially exposing users to security risks.

Recommendation

To mitigate this risk, configure your server to send the X-Content-Type-Options header with the value set to nosniff. This instructs browsers not to perform MIME sniffing and to strictly respect the declared content type.

References

Related Issues

Tags:
HTTP Headers
MIME Sniffing
Application Misconfiguration
Anything's wrong? Let us know Last updated on May 13, 2024

Use SmartScanner Free version to test for this issue

Download