---
name: azion-mitigate-the-httpoxy-vulnerability
description: >-
  Remove the Proxy header from requests to an application with a Rules Engine rule, so that HTTPoxy requests cannot redirect outgoing traffic.
---

# Mitigate the HTTPoxy vulnerability

You can protect an application against HTTPoxy from Azion Console with a [Rules Engine](/en/documentation/platform/applications/rules-engine/) rule that strips the `Proxy` header from every request. For the general procedure to add and order rules, refer to [Create an application rule](/en/documentation/guides/application-development/getting-started/work-with-rules-engine/).

HTTPoxy targets web applications that run in Common Gateway Interface (CGI) or CGI-like environments. CGI handles user requests and passes data between client and server through environment variables. In these environments, a `Proxy` request header overwrites the `HTTP_PROXY` environment variable, which sets the outgoing proxy. An attacker can then send the internal requests of the application to an external proxy server and capture every piece of data they carry. For more information, refer to the [HTTPoxy website](https://httpoxy.org/) or the [CERT Coordination Center (CERT/CC) vulnerability database](https://www.kb.cert.org/vuls/id/797896).

---

## Prerequisites

- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- An [application](/en/documentation/platform/applications/) that receives the requests to protect.

---

## Filter the Proxy header

The rule runs in the Request Phase and uses the *Filter Request Header* behavior, which requires no other Product on the application. A criterion of `${uri}` with `starts_with` and `/` matches every request, so the rule covers the whole application.

To create the rule in Azion Console:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications**, then select the application to protect.

2. **Select the Rules Engine tab**

3. **Select + Rule**

4. **Name the rule**

   Enter a name for the rule.

5. **Select Request Phase**

6. **Set the criterion**

   In the **Criteria** section, select `${uri}` as the variable and `starts_with` as the operator, and enter `/` as the argument.

7. **Add the behavior**

   In the **Behaviors** section, select *Filter Request Header* and enter `proxy` as the argument.

8. **Select Save**

The application removes the `Proxy` header from every request before it reaches your origin, so an HTTPoxy request cannot set the outgoing proxy.

---

## Next steps

- [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine.md#filter-request-header): Read what Filter Request Header removes in each phase and its API type.
- [Create an application rule](/en/documentation/guides/application-development/getting-started/work-with-rules-engine.md): Add, order, and edit the rules of an application.
