Vulnerabilities/

Qwik City has a CSRF Protection Bypass via Content-Type Header Validation

Severity:
Medium

Description

Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be abused by a remote attacker to circumvent form submission CSRF protections using specially crafted or multi-valued Content-Type headers.

Recommendation

Update the @builder.io/qwik-city package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@builder.io/qwik-city
Anything's wrong? Let us know Last updated on February 04, 2026