Internet's Invisible Enemy: Detecting and Measuring Web Cache Poisoning in the Wild
Yuejia Liang, Jianjun Chen, Run Guo, Kaiwen Shen, Hui Jiang, Man Hou, Yue Yu, Haixin Duan
Abstract
Web cache poisoning (WCP) has posed significant threats to Internet security by causing the cache server to deliver malicious responses to innocent users. This results in widespread denial of access to website resources and potential injection of harmful payloads. However, prior works on WCP vulnerability have been fragmented and conducted in a case-by-case form, lacking a systematic analysis of the threat landscape. In this paper, we fill this research gap by conducting a systematic evaluation of WCP vulnerabilities at scale. We propose HCache, a novel testing methodology to facilitates the widespread identification of WCP vulnerabilities. We evaluated our methodology against Tranco Top 1000 domains and their subdomains, and found that over 1,000 websites across 172 domains, representing 17% of the evaluated domains, are vulnerable to WCP. In particular, we have identified 7 new attack vectors stemming from previously unexplored caching headers. We have responsibly disclosed the vulnerabilities to the affected websites and received acknowledgements and bug bounties from world-famous companies, such as Alibaba, Adobe, Huawei, and Microsoft.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 53edd717-9bd8-4f55-927b-974633938c68Cited by top-tier papers4
- Identifying Logical Vulnerabilities in QUIC ImplementationsKaihua Wang, Jianjun Chen, Pinji Chen, Jianwei Zhuge et al.NDSS 2026 · 1 citation
- SIPConfusion: Exploiting SIP Semantic Ambiguities for Caller ID and SMS SpoofingQi Wang, Jianjun Chen, Jingcheng Yang, Jiahe Zhang et al.NDSS 2026 · 1 citation
- H3Act: Automated Measuring Semantic Conversion Anomalies of HTTP/3-to-HTTP/1.1 Translation in CDNsQihang Peng, Siyuan Tian, Yongxin Qiu, Jinyang Huang et al.USENIX Security 2026
- The Silent Danger in HTTP: Identifying HTTP Desync Vulnerabilities with Gray-box TestingKeran Mu, Jianjun Chen, Jianwei Zhuge, Qi Li et al.USENIX Security 2025
Builds on8
- Host of Troubles: Multiple Host Ambiguities in HTTP ImplementationsJianjun Chen, Jian Jiang, Hai-Xin Duan, Nicholas Weaver et al.CCS 2016 · 49 citations
- Your Cache Has Fallen: Cache-Poisoned Denial-of-Service AttackHoai Viet Nguyen, Luigi Lo Iacono, Hannes FederrathCCS 2019 · 41 citations
- T-Reqs: HTTP Request Smuggling with Differential FuzzingBahruz Jabiyev, Steven Sprecher, Kaan Onarlioglu, Engin KirdaCCS 2021 · 35 citations
- A Large-scale and Longitudinal Measurement Study of DKIM DeploymentChuhan Wang, Kaiwen Shen, Minglei Guo, Yuxuan Zhao et al.USENIX Security 2022
- Web Cache Deception Escalates!Seyed Ali Mirheidari, Matteo Golinelli, Kaan Onarlioglu, Engin Kirda et al.USENIX Security 2022
Related papers
- Cached and Confused: Web Cache Deception in the WildSeyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo et al.USENIX Security 2020
- Poisoned by the Host: Large-Scale Measurement of Host Name Poisoning in Web ApplicationsRui Yang, Haoyu Wang, Zhicheng Sun, Zhengyu Liu et al.S&P 2026 · 1 citation
- Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern WebMarco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara et al.USENIX Security 2021 · 30 citations
- More Haste, Less Speed: Cache Related Security Threats in Continuous Integration ServicesYacong Gu, Lingyun Ying, Huajun Chai, Yingyuan Pu et al.S&P 2024 · 4 citations
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 2 citations
