A reverse proxy / API gateway security scanner — TLS, HTTP security headers, header trust boundaries, and exposed management interfaces.
proxyaudit dynamically tests whether a reverse proxy or API gateway is
securely configured: TLS/transport, HTTP security headers, client-IP/header
trust boundaries, and information disclosure via exposed management
interfaces. Its check engine (proxy/) is built on
harnessx, the same check
orchestration library used by VulnAPI
and jwtop — part of the
CerberAuth DAST portfolio.
|
go install go install github.com/cerberauth/proxyaudit@latest |
Homebrew brew install cerberauth/tap/proxyaudit |
Docker docker run --rm ghcr.io/cerberauth/proxyaudit scan <url> |
See the installation guide for more options (Scoop, apt/yum/apk, Arch, Snap, winget, Chocolatey).
proxyaudit scan https://proxy.example.comFlags:
--aggressive Enable Agg-tier checks (no effect in v0.1 — no Agg-tier checks exist yet)
--engine string Hint the fronting proxy engine: nginx, traefik, envoy, caddy, or haproxy (optional, overrides auto-detection)
--format string terminal display format (default "terminal")
--no-color disable ANSI colors in terminal output
--output string file path to additionally write the report to
--output-format string format for --output (default "json")
--quiet suppress terminal display of the report
--report-url string HTTP endpoint to POST the report to
--report-header stringToString additional HTTP headers for the report transport (key=value)
--report-format string format for --report-url (default "json")
--show-all-findings show every finding on stdout, not just vulnerable ones
Exit codes: 0 no findings, 1 findings present, 2 runtime/connection
error — standard for CI usage. See the GitHub Actions guide
for CI examples.
Every check is non-destructive and read-only (single or few requests, no brute-forcing or state mutation). Use only against systems you own or have explicit written permission to test.
See the checks reference for the full list with CWE/OWASP mapping and remediation.
- TLS/Transport: protocol version, cipher strength/forward secrecy, certificate chain/expiry/hostname/OCSP stapling, HTTP→HTTPS redirect, HSTS.
- HTTP Security Headers: CSP, X-Frame-Options/frame-ancestors, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Server/ X-Powered-By banner disclosure, cookie flags.
- Client-IP & Header Trust Boundary: X-Forwarded-For, X-Real-IP,
True-Client-IP, X-Forwarded-Host reflection, Host header injection,
virtual-host confusion via a crafted Host header, RFC 7239
Forwardedvs. legacy header consistency, and IP-based access control bypass via a spoofed client-IP header. - Information Disclosure & Exposed Management Interfaces: verbose error pages, exposed proxy admin/status interfaces (Traefik, HAProxy, Envoy, nginx, Apache), directory listing, config/secrets file exposure.
Full documentation, including installation options, the CLI reference, the checks reference, and CI/Docker guides, is at cerberauth.com/docs/proxyaudit.
Issues and pull requests are welcome. Run the test suite with:
go build ./...
go vet ./...
go test ./...MIT — see LICENSE.