正式なドキュメントは英語版であり、この日本語訳はAI支援翻訳により作成された参考用のものです。日本語訳の一部の内容は人間によるレビューがまだ行われていないため、翻訳のタイミングにより英語版との間に差異が生じることがあります。最新かつ正確な情報については、英語版をご参照ください。

Missing Content-Type header

Description

The Content-Type header ensures that user agents correctly interpret the data being received. Without this header being sent, the browser may misinterpret the data, leading to MIME confusion attacks. If an attacker were able to upload files that are accessible by using a browser, they could upload files that may be interpreted as HTML and so execute Cross-Site Scripting (XSS) attacks.

Remediation

Ensure all resources return a proper Content-Type header that matches their format. As an example, when returning JavaScript files, the response header should be: Content-Type: application/javascript

For added protection, all resources should return the X-Content-Type-Options: nosniff header to disable user agents from mis-interpreting resources.

Details

IDAggregatedCWETypeRisk
16.1true16PassiveLow