> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# Web cache poisoning via ambiguous requests

> PortSwigger Web Security Academy lab: Web cache poisoning via ambiguous requests. Topic: HTTP Host Header Attacks.

# Web cache poisoning via ambiguous requests

<p className="machine-summary"><span className="prompt"><code>\$ tldr</code></span> PortSwigger · HTTP Host Header Attacks</p>

<div className="machine-meta">
  | ·            | ·                                                                                                                              |
  | ------------ | ------------------------------------------------------------------------------------------------------------------------------ |
  | Platform     | PortSwigger Web Security Academy                                                                                               |
  | Topic        | HTTP Host Header Attacks                                                                                                       |
  | Difficulty   | <span className="dbadge dbadge-medium">PRACTITIONER</span>                                                                     |
  | Official lab | [Open](https://portswigger.net/web-security/host-header/exploiting/lab-host-header-web-cache-poisoning-via-ambiguous-requests) |
</div>

## Solve the lab

| Language | Author          | Format | Link                                                                                                                           |
| -------- | --------------- | ------ | ------------------------------------------------------------------------------------------------------------------------------ |
| 🇬🇧 EN  | **PortSwigger** | Texto  | [Open](https://portswigger.net/web-security/host-header/exploiting/lab-host-header-web-cache-poisoning-via-ambiguous-requests) |

## Resources by skill

| Skill                                     | Source      | Link                                                             |
| ----------------------------------------- | ----------- | ---------------------------------------------------------------- |
| Web Cache Attacks (Poisoning / Deception) | PortSwigger | [Open](https://portswigger.net/web-security/web-cache-deception) |
| HTTP Host Header Attacks                  | PortSwigger | [Open](https://portswigger.net/web-security/host-header)         |

## Related skills

[Web Cache Attacks (Poisoning / Deception)](/en/skills/web-cache-attacks) · [HTTP Host Header Attacks](/en/skills/host-header-attacks)

***

## Comments & tips

Solved this lab a different way? Share it here — comments live in [GitHub Discussions](https://github.com/FFuson/HTB_Writeups/discussions).

<div className="rootea-giscus-wrap" data-giscus-term="lab:host-header-exploiting-host-header-web-cache-poisoning-via-ambiguous-requests" data-giscus-lang="en" />

*Last updated: 2026-05-08*

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"TechArticle","name":"Web cache poisoning via ambiguous requests","headline":"Web cache poisoning via ambiguous requests — PortSwigger lab index","url":"https://rootea.es/en/portswigger/labs/host-header/exploiting-host-header-web-cache-poisoning-via-ambiguous-requests","inLanguage":"en","about":[{"@type":"Thing","name":"PortSwigger Web Security Academy"},{"@type":"Thing","name":"HTTP Host Header Attacks"}],"isPartOf":{"@type":"WebSite","name":"rootea.es","url":"https://rootea.es"},"author":{"@type":"Organization","name":"rootea.es"}}`}
</script>
