Rust Unsafe X Frame Options Header
Description
This detector identifies unsafe X-Frame-Options header configurations in Rust web applications using the actix_web framework. The X-Frame-Options header helps prevent clickjacking attacks by controlling whether a page can be displayed in a frame, and incorrect configurations can leave applications vulnerable to UI redressing attacks.
Detection Strategy
• Code must import or use the 'actix_web' library for Rust web development
• Scanner analyzes HTTP header configuration calls in the code
• Specifically looks for X-Frame-Options header assignments or configurations
• Reports a vulnerability when X-Frame-Options header is set to unsafe values or configured incorrectly
• Triggers when header allows framing from untrusted sources (e.g., missing, set to ALLOWALL, or improperly configured)
Vulnerable code example
use actix_web::middleware::DefaultHeaders;
use actix_web::{middleware, App, HttpResponse};
fn app_with_xframe() -> App<()> {
// Vulnerable: Setting X-Frame-Options via DefaultHeaders middleware
App::new().wrap(middleware::DefaultHeaders::new().add(("X-Frame-Options", "DENY")))
}
...✅ Secure code example
use actix_web::middleware::DefaultHeaders;
use actix_web::{middleware, App, HttpResponse};
fn app_with_xframe() -> App<()> {
// Safe: Use Content-Security-Policy frame-ancestors instead of X-Frame-Options
App::new().wrap(middleware::DefaultHeaders::new().add(("Content-Security-Policy", "frame-ancestors 'self'")))
}
...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.